Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mac Users Targeted by Fake CAPTCHA for Data Theft

Mac Users Targeted by Fake CAPTCHA for Data Theft

Posted on August 24, 2026 By CWS

Mac users are facing a new cybersecurity threat involving a fake CAPTCHA campaign. The scam tricks users into executing commands that lead to password theft, remote control access, and unauthorized cryptocurrency mining.

How the Fake CAPTCHA Operates

The scheme entices users to execute a command in their Terminal instead of downloading an application. Disguised as a TrustKey human verification page, it mimics an ‘I’m not a robot’ checkbox. When selected, it copies a command to the clipboard and instructs the user to paste it into Terminal, circumventing standard security checks.

According to a report by NetbyteSEC shared with Cyber Security News, the investigation into this macOS threat began in July 2026. The command retrieves and executes code from a Cloudflare Worker using AppleScript, avoiding the installation of any visible software.

Implications of the Attack

The deceptive campaign goes beyond stealing a single login. It installs a persistent agent that captures the Mac’s login password, siphons browser and wallet information, and can deploy XMRig for cryptojacking. This underscores the dangers of malicious CAPTCHA loaders.

The initial command connects to a Cloudflare Worker that delivers an encoded AppleScript. This script establishes a LaunchAgent, allowing the malware to persist through system restarts. Using a method called EtherHiding, it queries a Polygon smart contract to find its command server, making it difficult for defenders to block.

Protecting Against the Threat

The malware further deploys a backdoor that communicates with a server for new instructions. It presents a fake macOS System Preferences prompt to capture the user’s password, storing it locally for later misuse.

Users should treat any CAPTCHA requesting Terminal or command tool access as suspicious. Genuine verification processes do not require such actions. To stay safe, users should close such pages immediately. The ClickFix method exemplifies how these tactics can deliver diverse payloads.

Future Risks and Recommendations

The malware can download a full or lightweight version of the Atomic macOS Stealer (AMOS), targeting browser profiles, keychain data, and more. This highlights the ongoing risk to Mac users who may believe their systems are immune to such threats.

Organizations should monitor for unusual Terminal-launched AppleScript activity, unexpected LaunchAgents, and suspicious RPC requests. Individuals who have been affected should disconnect their networks, change passwords using a clean device, and conduct a thorough system examination to remove the persistent backdoor before resuming normal use.

Cyber Security News Tags:AppleScript, Backdoor, CAPTCHA scam, Cloudflare Worker, cryptocurrency mining, Cryptojacking, Cybersecurity, EtherHiding, LaunchAgent, Mac security, Malware, Node.js attack, password theft, Phishing, terminal command

Post navigation

Previous Post: Venezuelan Given Longest Sentence for ATM Fraud
Next Post: Control AI-Induced Remediation Debt in Software Development

Related Posts

Zerobot Malware Targets Tenda Routers and n8n Platforms Zerobot Malware Targets Tenda Routers and n8n Platforms Cyber Security News
Hugging Face Considers  Billion Sale Amid AI Security Event Hugging Face Considers $13 Billion Sale Amid AI Security Event Cyber Security News
Google Unveils AI-Powered CodeMender for Enhanced Security Google Unveils AI-Powered CodeMender for Enhanced Security Cyber Security News
Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems Cyber Security News
VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root VMware Tools and Aria Operations Vulnerabilities Let Attackers Escalate Privileges to Root Cyber Security News
Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Broadcom Addresses 91 Security Flaws in Spring Framework
  • New Malware Threats: WordlistLoader and SynkLoader Unveiled
  • New SynkLoader Malware Targets Microsoft Teams Users
  • Uber Hit with $1 Billion Fine by Dutch Over Automated Driver Bans
  • Control AI-Induced Remediation Debt in Software Development

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Broadcom Addresses 91 Security Flaws in Spring Framework
  • New Malware Threats: WordlistLoader and SynkLoader Unveiled
  • New SynkLoader Malware Targets Microsoft Teams Users
  • Uber Hit with $1 Billion Fine by Dutch Over Automated Driver Bans
  • Control AI-Induced Remediation Debt in Software Development

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark