Widespread Fake CAPTCHA Campaign Delivering Malware
ID: 242422e9-6a02-52d5-b293-68ff25aaa7ba
STIX ID: report--242422e9-6a02-52d5-b293-68ff25aaa7ba
Feed Name: Arctic Wolf
Arctic Wolf has observed a campaign in which compromised websites present a fake CAPTCHA that instructs users to run a command (via the Windows Run dialog), triggering PowerShell execution that ultimately installs information-stealer malware; examples include HEP2go and several auto dealership sites. Arctic Wolf recommends avoiding sites showing such CAPTCHAs, deploying Arctic Wolf Agent and Sysmon for detection, and conducting security awareness training while detections for malicious PowerShell substrings are in place.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
