Using CAPTCHA for Compromise: Hackers Flip the Script
ID: 454e277f-3001-5016-b042-2d3afe49706b
STIX ID: report--454e277f-3001-5016-b042-2d3afe49706b
Feed Name: ReliaQuest Blog
Threat Score
ReliaQuest reports an active campaign (Sept–Dec 2024) using fake CAPTCHA pages impersonating services like CloudFlare and Google to silently copy malicious commands to victims' clipboards and trick them into executing scripts via Windows Run or PowerShell; the campaign distributes infostealers (Lumma, StealC) and NetSupport RAT, includes IoCs/domains, and documents detection/response guidance and automated playbooks to contain infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
