Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malware Uses Fake CAPTCHAs to Steal Information

New Malware Uses Fake CAPTCHAs to Steal Information

Posted on February 24, 2026 By CWS

A newly identified malware campaign is using counterfeit CAPTCHA pages to deceive users and deploy a sophisticated information-stealing tool. This campaign, first detected in early 2026, exhibits similarities to the ClickFix operation, which targeted restaurant booking systems in mid-2025.

Social Engineering Tactics Enhanced

The perpetrators have advanced their social engineering techniques, making it easier for them to bypass conventional security defenses and gain initial access to victims’ systems. The attack begins when a user visits a compromised site that displays a fraudulent CAPTCHA verification page. This page manipulates the user into copying a harmful PowerShell command to their clipboard and executing it manually.

By exploiting human interaction, this approach, known as the “ClickFix” technique, circumvents security mechanisms that typically examine file downloads rather than manual command executions. The command initiates a download from the attacker’s infrastructure, specifically the IP address 91.92.240.219, and verifies user actions via specific API calls before proceeding.

Detailed Analysis of Infection Process

Upon execution, the malicious script launches a multi-stage infection designed to extract sensitive information. The malware targets a broad range of applications, including over twenty-five web browsers, cryptocurrency wallets like MetaMask, and enterprise VPN configurations. Cybersecurity analysts have observed that the campaign checks for virtual environments and active security tools before data exfiltration.

The impact is profound, as attackers gain access to critical credentials and financial resources, enabling them to monetize compromised accounts or infiltrate deeper into corporate networks.

Stealth Techniques and Persistence

The malware employs advanced process injection methods to remain undetected on infected devices. Following the initial PowerShell execution, it retrieves a shellcode file named cptch.bin from the attacker’s servers. Analysts identified an operational security error when the attacker used the variable $finalPayload, which was flagged by Microsoft Defender. This shellcode, generated using the Donut framework, executes directly in memory.

To maintain persistence, the attackers alter the RunMRU registry key, ensuring the malicious PowerShell command is re-executed upon system startup. This persistence strategy grants long-term access and involves rotating payload filenames, such as cptchbuild.bin, to evade hash-based blocking mechanisms.

Organizations are advised to educate users about the dangers of executing commands from web pages. Security teams should monitor for unusual PowerShell activity and specific registry changes. Implementing endpoint detection rules that flag clipboard data reading by browser processes can help identify this threat early.

Cyber Security News Tags:CAPTCHA, cyber attack, Cybersecurity, data breach, information stealer, Malware, PowerShell, security tools, social engineering, virtual environments

Post navigation

Previous Post: GitHub Codespaces Vulnerability Exploited for Repository Control
Next Post: Effective Identity Risk Management in Modern Enterprises

Related Posts

GrayCharlie Targets WordPress Sites with Malicious Scripts GrayCharlie Targets WordPress Sites with Malicious Scripts Cyber Security News
New Android Bug Impacts Volume Buttons Functionality with “Select to Speak” Enabled New Android Bug Impacts Volume Buttons Functionality with “Select to Speak” Enabled Cyber Security News
ScarCruft Exploits Gaming Platform with Backdoor Attacks ScarCruft Exploits Gaming Platform with Backdoor Attacks Cyber Security News
Choosing the Right Tool for Network Penetration Testing Choosing the Right Tool for Network Penetration Testing Cyber Security News
Hackers Exploit VLC to Deploy ValleyRAT Malware Hackers Exploit VLC to Deploy ValleyRAT Malware Cyber Security News
Cursor AI Code Editor RCE Vulnerability Enables “autorun” of Malicious on your Machine Cursor AI Code Editor RCE Vulnerability Enables “autorun” of Malicious on your Machine Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mysterious Ox Alpha AI Offers Free Tokens to Coders
  • Hackers Exploit Search Engines with Phishing Pages
  • Microsoft Teams Introduces Bot-Blocking Policy for Meetings
  • Zimbra Vulnerability Exploitation Demands Immediate Action
  • ReliaQuest Hit by ShinyHunters, Limits Damage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mysterious Ox Alpha AI Offers Free Tokens to Coders
  • Hackers Exploit Search Engines with Phishing Pages
  • Microsoft Teams Introduces Bot-Blocking Policy for Meetings
  • Zimbra Vulnerability Exploitation Demands Immediate Action
  • ReliaQuest Hit by ShinyHunters, Limits Damage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark