logo

“Clipboard Hijacking” A Fake CAPTCHA Leverage Pastejacking Script Via Hacked Sites To Steal Clipboard Data

ID: bef4a36b-d754-5acf-8606-73db202f22eb

STIX ID: report--bef4a36b-d754-5acf-8606-73db202f22eb

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-04-05

Date Updated: 2026-04-21

Author: Balaji N

...
...

Unit 42 describes the "KongTuke" campaign where compromised legitimate websites inject scripts that redirect visitors to fake CAPTCHA pages which silently place a malicious PowerShell command in the clipboard; users are socially engineered to paste and run it, causing the system to contact remote IPs/domains for further payloads and C2 communications—IOCs are provided but the final payload remains unidentified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.