Hackers in X are exploiting the news surrounding Ross Ulbricht to direct unsuspecting users to a Telegram channel that tricks them into executing malicious PowerShell code via captcha.
See also: Telegram update brings third-party verification system

The attack, spotted by vx-underground, is a new variation of the “Click-Fix” tactic that has become very popular among threat actors for distributing malware over the past year. However, instead of fixing common errors, this variant pretends to be a captcha or verification system that users must complete to join the Telegram channel.
Last month, researchers from Guardio Labs and Infoblox uncovered a new campaign that used CAPTCHA verification pages that prompt users to run PowerShell to verify they are not a bot.
Ross Ulbricht is the founder and main operator of the infamous dark web marketplace Silk Road, which served as a hub for the sale and purchase of illegal goods and services. The man was sentenced to life in prison in 2015, which some found excessive given that he facilitated crimes and did not personally carry them out.
President Trump previously expressed the same view, promising to pardon Ulbricht once he became President of the United States, and recently fulfilled that promise.
See also: Criminals in Southeast Asia use Telegram
Hackers exploited this development, using fake but verified Ross Ulbricht accounts on X to direct individuals to malicious Telegram channels that appear as official Ulbricht gateways.

On Telegram, users are treated to a so-called identity verification request called “Safeguard,” which guides users through a fake verification process.
At the end, users are presented with a mini Telegram app that displays a fake captcha verification window. This mini app automatically copies a PowerShell command to the device's clipboard and then asks the user to open the Windows Run dialog, paste it, and execute it.
The code copied to the clipboard downloads and executes a PowerShell script, which ultimately downloads a ZIP file to https://openline[.]cyou.
This zip file contains several files, including ID-helper.exe [VirusTotal], which a comment on VirusTotal suggests may be a Cobalt Strike loader.
See also: Telegram: Will give phone numbers and IP addresses of users to the authorities
Malicious PowerShell scripts have become a common tool for attackers due to their flexibility and powerful capabilities. These scripts can be used to bypass traditional security measures, execute commands remotely, and deliver payloads without relying on external files. Their ability to run natively in Windows makes them difficult to detect. Attackers often use PowerShell to obfuscate code, hide malicious intent, and evade detection mechanisms, which highlights the importance of implementing proper monitoring and security practices to mitigate such threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
