Skip to main content
Skip to main content
Microsoft Security Intelligence
Published May 20, 2025 | Updated May 23, 2025

TrojanDownloader:PowerShell/FakeCaptcha.TKY!MTB

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

TrojanDownloader:PowerShell/FakeCaptcha.TKY!MTB is a social engineering attack used by threat actors to deceive users into introducing malicious PowerShell code into the Windows Terminal, often then downloading additional malware from an actor-controlled server.

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us