HomeSecurityPhantomCaptcha: New ClickFix attack targets Ukraine

PhantomCaptcha: New ClickFix attack targets Ukraine

A spear-phishing attack targeted members of the Ukrainian regional government and organizations critical to the war relief effort in Ukraine , including the International Committee of the Red Cross, UNICEF, and various NGOs. The campaign, dubbed PhantomCaptcha , attempted to trick victims into executing commands used in attacks ClickFix . They were disguised as Cloudflare CAPTCHA verification prompts to install a WebSocket Remote Access Trojan (RAT).

PhantomCaptcha ClickFix Ukraine

SentinelLABS reports that the campaign began and ended on October 8, but the attacker had devoted significant time and effort to creating the necessary infrastructure, as some domains used in the operation were registered in late March.

See also: Iranian MuddyWater targets over 100 organizations in new campaign

PhantomCaptcha: How did the attack work?

The attacks began with emails, which appeared to come from the Office of the President of Ukraine, and contained malicious PDF that linked to a domain that pretended to be the Zoom.

When users clicked on the fake Zoom session link, they saw an automated check process before being redirected to the communication platform. During this phase, a client identifier is generated and sent to the attacker's server over a WebSocket connection.

PhantomCaptcha: New ClickFix attack targets Ukraine

“If the WebSocket server responded with a matching identifier, the victim’s browser would be redirected to a legitimate, password-protected Zoom session,” SentinelLABS’ analysis showed. According to the researchers, this path likely led the attacker to engage in calls social engineering with the victim.

See also: Sharepoint: Chinese target organizations via ToolShell vulnerability

If the client ID didn’t match, visitors had to go through another security check and prove they were real people and not robots. They could complete the fake CAPTCHA verification by following instructions in Ukrainian, which asked them to press a button to copy a “token” and paste it into the Windows Command Prompt.

The copy/paste action executed a PowerShell command that downloaded and executed a malicious script to deliver the second-stage payload, which was a reconnaissance and system-profiler tool. The tool collects system data such as the computer name, domain information, username, process ID, and system UUID, and sends it to the command and control (C2) server.

The payload is a lightweight WebSocket RAT capable of remote command execution and data extraction via base64-encoded JSON commands.

See also: PassiveNeuron APT uses Neursite and NeuralExecutor

PhantomCaptcha: New ClickFix attack targets Ukraine

Researchers found that the short-lived campaign was linked to a subsequent operation targeting users in Lviv, Ukraine, with Android APKs or cloud storage tools. These apps act as spyware, tracking the victim’s real-time location, call logs, contact list, and images.

While SentinelLABS did not attribute the ClickFix attacks to a specific group, the researchers note that the WebSocket RAT was hosted on Russian infrastructure and the adult-themed campaign may be related to deployment from Russia/Belarus.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS