logo

PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation

Threat Score
85/100

Date Published: 2025-10-22

Date Updated: 2026-07-27

Author: Tom Hegel

...
...

SentinelLABS and Digital Security Lab of Ukraine describe the PhantomCaptcha spearphishing campaign that used weaponized PDFs impersonating the Ukrainian President’s Office to redirect victims to fake Cloudflare/Zoom pages which social-engineered users into pasting and executing PowerShell commands; the attack delivered a three-stage PowerShell payload (obfuscated downloader → fingerprinting/encrypted comms → WebSocket-based RAT) and a separate Android infostealer (princess.apk) for data exfiltration, with extensive infrastructure, hashes, IPs, domains, and mitigation guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.