PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation
ID: 4b49df92-b255-5373-bdd6-9b6e9368942f
STIX ID: report--4b49df92-b255-5373-bdd6-9b6e9368942f
SentinelLABS and Digital Security Lab of Ukraine describe the PhantomCaptcha spearphishing campaign that used weaponized PDFs impersonating the Ukrainian President’s Office to redirect victims to fake Cloudflare/Zoom pages which social-engineered users into pasting and executing PowerShell commands; the attack delivered a three-stage PowerShell payload (obfuscated downloader → fingerprinting/encrypted comms → WebSocket-based RAT) and a separate Android infostealer (princess.apk) for data exfiltration, with extensive infrastructure, hashes, IPs, domains, and mitigation guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
