logo

PhantomCaptcha ClickFix attack targets Ukraine war relief orgs

ID: 4b935c5c-bab0-5152-bbc8-372301b91529

STIX ID: report--4b935c5c-bab0-5152-bbc8-372301b91529

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-22

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

SentinelLabs reported a one-day spearphishing campaign (PhantomCaptcha) that targeted Ukrainian regional government and war-relief organizations on October 8, using malicious PDFs and fake Zoom links that displayed a counterfeit Cloudflare CAPTCHA; victims who followed instructions ran a PowerShell 'ClickFix' command that installed a reconnaissance utility and a WebSocket RAT for remote command execution and data exfiltration, with a linked follow-on operation distributing Android spyware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.