The CAPTCHA Trap: ClearFake Malware Tricks Users Into Hacking Themselves
ID: 54e27c20-0ee7-52a1-be0d-c1017ee75277
STIX ID: report--54e27c20-0ee7-52a1-be0d-c1017ee75277
Feed Name: securityonline.info
A sophisticated campaign named ClearFake lures users with fake CAPTCHA prompts that instruct victims to paste a malicious PowerShell command from their clipboard; attackers then abuse a vulnerable Windows script (SyncAppvPublishingServer.vbs) to execute PowerShell stealthily. The campaign stores Base64-encoded JavaScript payloads in immutable Binance Smart Chain smart contracts ("EtherHiding") and leverages jsDelivr CDN to frustrate blocking, enabling takedown-resistant distribution; researchers estimate ~150,000 infections since August 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
