Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential-Stealing Malware
Attackers trick users into clicking fake Google CAPTCHA prompts that secretly install malware. The malware then steals passwords and other account data.
- Report priority
- Medium
- Targets
How it works
- Attackers send fake Google CAPTCHA prompts via email or websites.
- When users click them, the fake CAPTCHA page secretly downloads and runs a malicious file.
- That file connects to a hidden server and steals passwords, cookies, and other account data.
- The stolen data is sent to attackers' servers.
- No Google service is involved; this is a phishing trick.
What to do
If you clicked a fake CAPTCHA prompt from an email or website, check your computer for unexpected programs or unusual activity. If you see unfamiliar files or your browser behaves strangely, do not click fake CAPTCHA prompts from unknown sources. Google services are not involved.
If you think your device is infected, run a full antivirus scan. Use Google's official security tools to check for stolen data. If you entered credentials on the fake site, change passwords for all accounts immediately.
Technical details
A user receives an email claiming to be from Google, asking them to verify their account by solving a CAPTCHA. When they click the link, they see a fake CAPTCHA page. After 'solving' it, malware is installed on their computer without their knowledge. The malware then steals their passwords and sends them to attackers.
A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain smart contracts to deploy the Amatera information stealer.