Cybersecurity researchers have uncovered a sophisticated malware campaign that leverages deceptive CAPTCHA verification pages to distribute a new Rust-based information-stealing tool called EDDIESTEALER .
See also: Katz Stealer targets Chrome, Edge, Brave and Firefox

This campaign is a significant development in social engineering tactics, as cybercriminals exploit users' familiarity with standard security verification procedures to mislead them and execute malicious code.
EDDIESTEALER uses a complex, multi-stage propagation mechanism, starting with compromised websites displaying convincing fake “ I’m not a robot ” verification screens. Ultimately, this leads to the installation of a powerful data-sniffing tool capable of collecting credentials, browser information, and cryptocurrency wallet data .
The attack channel demonstrates remarkable sophistication in its implementation methodology. Initial access is achieved via compromised websites, which load disguised JavaScript payloads , presenting users with a seemingly authentic Google reCAPTCHA.
These fake verification screens instruct users to perform seemingly innocent actions: press Windows + R to open the “Run” window, press Ctrl + V to paste the clipboard contents, and then press Enter to execute the command.
See also: Authorities disrupted the infrastructure of Lumma Stealer malware
Unbeknownst to the victim, the malicious JavaScript has already copied a PowerShell command to the clipboard using the document.execCommand("copy"). Elastic Security Labs analysts identified this emerging threat through extensive telemetry analysis, revealing that the campaign uses a sophisticated command structure to silently download secondary payloads from infrastructure controlled by the attackers.

The PowerShell command automatically retrieves a JavaScript file named “gverify.js” from domains such as hxxps://1111.fit/version/, which then downloads the main EDDIESTEALER, using a pseudo-randomly generated 12-character filename.
This multi-layered approach effectively masks the true nature of the attack, while maintaining the illusion of a legitimate system verification process. The impact of the malware goes far beyond simply stealing credentials, targeting a wide range of sensitive data, including cryptocurrency wallets, stored credentials from browsers, databases from password managers, FTP client settings, and messaging applications.
EDDIESTEALER demonstrates particular sophistication in tackling modern browser security mechanisms, employing techniques similar to those used by ChromeKatz to bypass application-based encryption protections introduced in recent versions of Chrome. The malware’s ability to adapt to evolving security measures highlights the ongoing threat posed by well-organized and well-equipped cybercriminal groups.
See also: New Chihuahua Infostealer targets browser data
In relation to the above, it is worth noting that the malicious use of "fake verification processes" is an ever-evolving form of social engineering, which exploits users' trust and habit towards familiar security screens, such as Google reCAPTCHA.
Source: cybersecuritynews
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
