Cybersecurity Reach Foundation
← All safety alerts
investigating

Fake Discord verification pages tell you to paste a PowerShell command

A page at discord-eu[.]cfd uses Discord branding and a Cloudflare-style human check. Its pop-up tells visitors to press Win + R, paste text with Ctrl + V, and press Enter. That is not a normal verification step: it can run a hidden PowerShell command on a Windows computer. Close the page and do not paste or run anything.

A fake Discord page showing a Cloudflare-style verification box and instructions to press Win plus R and paste a command
This Discord-branded page tells visitors to open the Windows Run dialog and paste a command. Do not follow those instructions.

Observed domain or link

  • discord-eu[.]cfd

What to do

  • Close the page and do not follow its instructions.
  • Do not press Win + R or paste anything into the Windows Run dialog, PowerShell, or Command Prompt.
  • If you pasted or ran the command, disconnect the computer from the internet and ask a trusted adult or qualified technician for help.
  • Change important passwords from a different clean device and revoke active sessions if the command was run.
  • Use the official Discord app or type the known Discord website address yourself instead of following an unexpected verification page.

What this alert does not establish

  • The page operator, exact payload, malware family, and number of people targeted were not confirmed.
  • The supplied command is encoded; do not decode or execute it on a normal computer as a way to investigate it.

Share this warning

This alert is also on WatchOut, our shareable alert feed, with one-tap sharing and free email alerts.

Observed:
Last updated:

This alert is maintained from the shared Cybersecurity Reach Foundation / ScamArchive alert record.