Threats Tagged 'captcha'
View all threats tagged with 'captcha'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'captcha'
Click on any threat for detailed analysis and mitigation recommendations
IClickFix is a malicious framework that compromises WordPress sites to distribute malware using the ClickFix social engineering tactic. Active since December 2024, it has infected over 3,800 WordPress sites globally. The framework injects malicious JavaScript into compromised sites, leading users through a fake CAPTCHA challenge that tricks them into executing malicious code. This ultimately installs NetSupport RAT, granting attackers full control of infected systems. The campaign has evolved over time, adding traffic distribution systems and refining its lures. While initially distributing Emmenhtal Loader and XFiles Stealer, it now primarily delivers NetSupport RAT. The widespread nature of the attacks suggests opportunistic exploitation rather than targeted campaigns. Join the discussion | AlienVault OTX General | 01/30/2026, 08:20:09 UTC Added: 01/30/2026, 08:43:08 UTC |
A coordinated spearphishing campaign targeted NGOs and Ukrainian government administrations involved in war relief efforts. The attack used emails impersonating the Ukrainian President's Office with weaponized PDFs, employing a fake Cloudflare captcha page to execute malware. The final payload was a WebSocket RAT enabling remote command execution and data exfiltration. Despite six months of preparation, the attackers' infrastructure was only active for one day, indicating sophisticated planning and operational security. An additional mobile attack vector was discovered, using fake applications to collect data from Android devices. The campaign demonstrated extensive operational planning, compartmentalized infrastructure, and deliberate exposure control. Join the discussion | AlienVault OTX General | 10/22/2025, 19:45:18 UTC Added: 10/22/2025, 19:52:59 UTC |
Palo Alto Unit42 have uncovered a phishing kit named the IUAM ClickFix Generator that automates the creation of these attacks. The kit is designed to generate highly customizable phishing pages that lure victims by mimicking browser verification challenges often used to block automated traffic. It includes advanced features such as operating system detection and clipboard injection, enabling low-effort, cross-platform malware deployment. Join the discussion | AlienVault OTX General | 10/10/2025, 17:59:02 UTC Added: 10/10/2025, 18:08:59 UTC |
Attackers are exploiting Scalable Vector Graphics (SVG) files to execute sophisticated phishing attacks. SVGs, typically used for scalable images, can contain embedded JavaScript that executes when opened in a browser. The attack chain involves sending SVG attachments via spear-phishing emails or cloud storage links. When opened, the SVG file launches in the default web browser, allowing embedded scripts to execute and redirect victims to phishing sites mimicking trusted services. The attackers use deceptive subject lines and innocuous-looking attachment names to avoid suspicion. The SVG contains encrypted malicious code that, when decrypted, redirects to a phishing site protected by a Cloudflare CAPTCHA gate. Organizations are advised to implement deep content inspection, disable automatic SVG rendering, educate employees, and monitor for unusual redirects and script activity. Join the discussion | AlienVault OTX General | 08/07/2025, 21:14:50 UTC Added: 08/07/2025, 21:47:44 UTC |
A novel Rust-based infostealer called EDDIESTEALER has been discovered, distributed through fake CAPTCHA campaigns. The malware uses deceptive verification pages to trick users into executing a malicious PowerShell script, which deploys the infostealer. EDDIESTEALER targets sensitive data including credentials, browser information, and cryptocurrency wallet details. It communicates with a command and control server to receive tasks and exfiltrate data. The malware employs string obfuscation, API obfuscation, and other evasion techniques. It specifically targets various crypto wallets, browsers, password managers, FTP clients, and messaging applications. The use of Rust in its development reflects a growing trend among threat actors seeking enhanced stealth and resilience against traditional analysis methods. Join the discussion | AlienVault OTX General | 05/29/2025, 19:24:48 UTC Added: 05/29/2025, 19:29:21 UTC |
Threat actors are exploiting user fatigue with anti-spam mechanisms through a technique called ClickFix. This method involves compromising websites and embedding fraudulent CAPTCHA images, which, when solved by unsuspecting users, lead to the execution of malicious code. The attack chain typically includes PowerShell commands and the use of legitimate Windows tools to download and execute additional payloads. Common malware delivered through this technique includes Lumma Stealer, NetSupport RAT, and SectopRAT. The success of ClickFix relies heavily on social engineering and user interaction, making user education and awareness crucial in mitigating these attacks. Recommendations include training users to recognize suspicious requests, restricting PowerShell execution, and deploying advanced EDR solutions. Join the discussion | AlienVault OTX General | 05/22/2025, 21:54:08 UTC Added: 05/23/2025, 13:06:58 UTC |
Showing 1 to 6 of 6 results