logo

The “Fake CAPTCHA” Trap: Malware Hides in Google Calendar & Images

ID: 1c10fe01-9f3f-51fa-8a2f-94264aab8d8d

STIX ID: report--1c10fe01-9f3f-51fa-8a2f-94264aab8d8d

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Ddos

...
...

This report from The Blackpoint SOC describes a sophisticated Fake CAPTCHA campaign that coerces users into executing commands via the Windows Run dialog, abuses the legitimate SyncAppvPublishingServer.vbs (a LOLBIN) to mask execution, fetches live configuration from a public Google Calendar, and retrieves an encrypted payload hidden in PNG images (steganography) which loads the Amatera Stealer to harvest browser data and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.