Fake CAPTCHA requests are used to distribute malware.
See also: Cyberattack causes MoneyGram service outage

A CAPTCHA is a type of challenge-response test used on computers to determine whether a user is human. These tests are designed to thwart automated programs and bots by requiring users to perform tasks that are easy for humans but challenging for machines. These tools help protect websites from spam and abuse by ensuring that only human users can perform certain actions, such as creating accounts or posting comments.
They typically present challenges such as “gnarled text,” “image recognition tasks,” or “audio prompts” that require human cognitive skills to solve. Recently, cybersecurity analysts at SecureWorks warned about fake CAPTCHA requests that deliver malware.
In September 2024, Secureworks incident responders uncovered two cases where users searching for video streaming services on Google were directed to malicious websites.
One victim was searching for sports streaming sites, while another was searching for movie streaming options. Both were redirected to a deceptive URL that prompted them to prove they were human by pressing specific key combinations:
- “Windows + R” to open the “Run” menu.
- “CTRL + V” to paste a coded PowerShell
- “Enter” to execute it
This CAPTCHA action triggered the download of a ZIP file containing malware, which was extracted to \AppData\Local\Temp\file\Setup.exe on the victims' computer.
See also: Deloitte denies user data is at risk after breach
The malware then executed additional tools, including a renamed BitTorrent application (StrCmp.exe) and a Windows utility called Search Indexer .

SecureWorks CTU researchers identified that this attack method was used to deploy infostealer malware, specifically variants known as Vidar and StealC, which are designed to collect sensitive data from infected systems.
This malware attack poses a significant risk by evading “browser security checks” and does so by exploiting a fake CAPTCHA to open a command prompt on the victim’s computer. The attacker then directs the user to execute unauthorized code and also deploy malware such as the “LummaC2 infostealer.”
This global campaign has been noted in other regions, such as the Middle East, Australia, and France, with reports taking place from May 2024 to September 2024.
See also: Vulnerability in Apache Tomcat allows Dos attacks
Organizations should be particularly cautious about employees who use corporate systems to access streaming services or other content , as they may be targeted by phishing campaigns that leverage this attack method.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
