HomeSecurityFake CAPTCHA requests contain malware

Fake CAPTCHA requests contain malware

Fake CAPTCHA requests are used to distribute malware.

See also: Cyberattack causes MoneyGram service outage

CAPTCHA malware

A CAPTCHA is a type of challenge-response test used on computers to determine whether a user is human. These tests are designed to thwart automated programs and bots by requiring users to perform tasks that are easy for humans but challenging for machines. These tools help protect websites from spam and abuse by ensuring that only human users can perform certain actions, such as creating accounts or posting comments.

They typically present challenges such as “gnarled text,” “image recognition tasks,” or “audio prompts” that require human cognitive skills to solve. Recently, cybersecurity analysts at SecureWorks warned about fake CAPTCHA requests that deliver malware.

In September 2024, Secureworks incident responders uncovered two cases where users searching for video streaming services on Google were directed to malicious websites.

One victim was searching for sports streaming sites, while another was searching for movie streaming options. Both were redirected to a deceptive URL that prompted them to prove they were human by pressing specific key combinations:

  • “Windows + R” to open the “Run” menu.
  • “CTRL + V” to paste a coded PowerShell
  • “Enter” to execute it

This CAPTCHA action triggered the download of a ZIP file containing malware, which was extracted to \AppData\Local\Temp\file\Setup.exe on the victims' computer.

See also: Deloitte denies user data is at risk after breach

The malware then executed additional tools, including a renamed BitTorrent application (StrCmp.exe) and a Windows utility called Search Indexer .

Fake CAPTCHA requests contain malware

SecureWorks CTU researchers identified that this attack method was used to deploy infostealer malware, specifically variants known as Vidar and StealC, which are designed to collect sensitive data from infected systems.

This malware attack poses a significant risk by evading “browser security checks” and does so by exploiting a fake CAPTCHA to open a command prompt on the victim’s computer. The attacker then directs the user to execute unauthorized code and also deploy malware such as the “LummaC2 infostealer.”

This global campaign has been noted in other regions, such as the Middle East, Australia, and France, with reports taking place from May 2024 to September 2024.

See also: Vulnerability in Apache Tomcat allows Dos attacks

Organizations should be particularly cautious about employees who use corporate systems to access streaming services or other content , as they may be targeted by phishing campaigns that leverage this attack method.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS