HomeSecurityTelegram captcha tricks you into running malicious PowerShell scripts

Telegram captcha tricks you into running malicious PowerShell scripts

Hackers in X are exploiting the news surrounding Ross Ulbricht to direct unsuspecting users to a Telegram channel that tricks them into executing malicious PowerShell code via captcha.

See also: Telegram update brings third-party verification system

Telegram captcha PowerShell scenarios

The attack, spotted by vx-underground, is a new variation of the “Click-Fix” tactic that has become very popular among threat actors for distributing malware over the past year. However, instead of fixing common errors, this variant pretends to be a captcha or verification system that users must complete to join the Telegram channel.

Last month, researchers from Guardio Labs and Infoblox uncovered a new campaign that used CAPTCHA verification pages that prompt users to run PowerShell to verify they are not a bot.

Ross Ulbricht is the founder and main operator of the infamous dark web marketplace Silk Road, which served as a hub for the sale and purchase of illegal goods and services. The man was sentenced to life in prison in 2015, which some found excessive given that he facilitated crimes and did not personally carry them out.

President Trump previously expressed the same view, promising to pardon Ulbricht once he became President of the United States, and recently fulfilled that promise.

See also: Criminals in Southeast Asia use Telegram

Hackers exploited this development, using fake but verified Ross Ulbricht accounts on X to direct individuals to malicious Telegram channels that appear as official Ulbricht gateways.

Telegram captcha tricks you into running malicious PowerShell scripts

On Telegram, users are treated to a so-called identity verification request called “Safeguard,” which guides users through a fake verification process.

At the end, users are presented with a mini Telegram app that displays a fake captcha verification window. This mini app automatically copies a PowerShell command to the device's clipboard and then asks the user to open the Windows Run dialog, paste it, and execute it.

The code copied to the clipboard downloads and executes a PowerShell script, which ultimately downloads a ZIP file to https://openline[.]cyou.

This zip file contains several files, including ID-helper.exe [VirusTotal], which a comment on VirusTotal suggests may be a Cobalt Strike loader.

See also: Telegram: Will give phone numbers and IP addresses of users to the authorities

Malicious PowerShell scripts have become a common tool for attackers due to their flexibility and powerful capabilities. These scripts can be used to bypass traditional security measures, execute commands remotely, and deliver payloads without relying on external files. Their ability to run natively in Windows makes them difficult to detect. Attackers often use PowerShell to obfuscate code, hide malicious intent, and evade detection mechanisms, which highlights the importance of implementing proper monitoring and security practices to mitigate such threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS