logo

Living Off the Web: How Trust Infrastructure Became a Malware Delivery Interface

ID: 8b8d7372-d574-5b55-9b15-cec879d3e990

STIX ID: report--8b8d7372-d574-5b55-9b15-cec879d3e990

Feed Name: Censys Blog

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-27

Author: Andrew Northern; Principal Security Researcher

...
...

This report analyzes the Fake Captcha ecosystem at scale, showing that visually uniform Cloudflare-style verification lures are a shared interface layer used to deliver malware via diverse, independent delivery pipelines (clipboard-driven VBScript/PowerShell, MSI installers, and server-driven Matrix Push C2). Using perceptual-hash clustering of screenshots from ~9,494 assets, the research finds a dominant visual cluster that fronts multiple incompatible execution models and infrastructure pools, demonstrating that visual similarity is a weak signal for attribution and that defenders must detect workflow abuse (notification opt-ins, service-worker/push activity, and context anomalies) rather than relying on payload-centric heuristics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.