logo

Using CAPTCHA for Compromise: Hackers Flip the Script

ID: 454e277f-3001-5016-b042-2d3afe49706b

STIX ID: report--454e277f-3001-5016-b042-2d3afe49706b

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-04-29

...
...

ReliaQuest reports an active campaign (Sept–Dec 2024) using fake CAPTCHA pages impersonating services like CloudFlare and Google to silently copy malicious commands to victims' clipboards and trick them into executing scripts via Windows Run or PowerShell; the campaign distributes infostealers (Lumma, StealC) and NetSupport RAT, includes IoCs/domains, and documents detection/response guidance and automated playbooks to contain infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.