Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mac Users Targeted by Fake CAPTCHA for Data Theft

Mac Users Targeted by Fake CAPTCHA for Data Theft

Posted on August 24, 2026 By CWS

Mac users are facing a new cybersecurity threat involving a fake CAPTCHA campaign. The scam tricks users into executing commands that lead to password theft, remote control access, and unauthorized cryptocurrency mining.

How the Fake CAPTCHA Operates

The scheme entices users to execute a command in their Terminal instead of downloading an application. Disguised as a TrustKey human verification page, it mimics an ‘I’m not a robot’ checkbox. When selected, it copies a command to the clipboard and instructs the user to paste it into Terminal, circumventing standard security checks.

According to a report by NetbyteSEC shared with Cyber Security News, the investigation into this macOS threat began in July 2026. The command retrieves and executes code from a Cloudflare Worker using AppleScript, avoiding the installation of any visible software.

Implications of the Attack

The deceptive campaign goes beyond stealing a single login. It installs a persistent agent that captures the Mac’s login password, siphons browser and wallet information, and can deploy XMRig for cryptojacking. This underscores the dangers of malicious CAPTCHA loaders.

The initial command connects to a Cloudflare Worker that delivers an encoded AppleScript. This script establishes a LaunchAgent, allowing the malware to persist through system restarts. Using a method called EtherHiding, it queries a Polygon smart contract to find its command server, making it difficult for defenders to block.

Protecting Against the Threat

The malware further deploys a backdoor that communicates with a server for new instructions. It presents a fake macOS System Preferences prompt to capture the user’s password, storing it locally for later misuse.

Users should treat any CAPTCHA requesting Terminal or command tool access as suspicious. Genuine verification processes do not require such actions. To stay safe, users should close such pages immediately. The ClickFix method exemplifies how these tactics can deliver diverse payloads.

Future Risks and Recommendations

The malware can download a full or lightweight version of the Atomic macOS Stealer (AMOS), targeting browser profiles, keychain data, and more. This highlights the ongoing risk to Mac users who may believe their systems are immune to such threats.

Organizations should monitor for unusual Terminal-launched AppleScript activity, unexpected LaunchAgents, and suspicious RPC requests. Individuals who have been affected should disconnect their networks, change passwords using a clean device, and conduct a thorough system examination to remove the persistent backdoor before resuming normal use.

Cyber Security News Tags:AppleScript, Backdoor, CAPTCHA scam, Cloudflare Worker, cryptocurrency mining, Cryptojacking, Cybersecurity, EtherHiding, LaunchAgent, Mac security, Malware, Node.js attack, password theft, Phishing, terminal command

Post navigation

Previous Post: Venezuelan Given Longest Sentence for ATM Fraud
Next Post: Control AI-Induced Remediation Debt in Software Development

Related Posts

Xerox FreeFlow Vulnerabilities leads to SSRF and RCE Attacks Xerox FreeFlow Vulnerabilities leads to SSRF and RCE Attacks Cyber Security News
Google Gemini Vulnerability Exploited via Messaging Apps Google Gemini Vulnerability Exploited via Messaging Apps Cyber Security News
Windows BitLocker Bypass Vulnerability Let Attackers Bypass Security Feature Windows BitLocker Bypass Vulnerability Let Attackers Bypass Security Feature Cyber Security News
Critical ExifTool Vulnerability Exposes macOS to Hidden Threats Critical ExifTool Vulnerability Exposes macOS to Hidden Threats Cyber Security News
Iran’s Internet Shutdown Enters 10th Day, Traffic Severely Restricted Iran’s Internet Shutdown Enters 10th Day, Traffic Severely Restricted Cyber Security News
CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Actively Exploited in Attacks CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Actively Exploited in Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Uber Hit with $1 Billion Fine by Dutch Over Automated Driver Bans
  • Control AI-Induced Remediation Debt in Software Development
  • Mac Users Targeted by Fake CAPTCHA for Data Theft
  • Venezuelan Given Longest Sentence for ATM Fraud
  • Anthropic’s Claude AI Faces Repeated Service Disruptions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Uber Hit with $1 Billion Fine by Dutch Over Automated Driver Bans
  • Control AI-Induced Remediation Debt in Software Development
  • Mac Users Targeted by Fake CAPTCHA for Data Theft
  • Venezuelan Given Longest Sentence for ATM Fraud
  • Anthropic’s Claude AI Faces Repeated Service Disruptions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark