More Than 5,400 Hacked Sites Using Fake CAPTCHAs to Spread Malware
More than 5,400 hacked websites worldwide are using fake CAPTCHAs (the authentication step that distinguishes humans from bots) to get Windows users to run malware. According to Netskope Threat Labs, more than 5,400 websites spanning over 2,200 organizations worldwide have been compromised in recent months. Many of the affected sites belong to small businesses, including clinics, plumbing companies, and online stores.
The attack begins when hidden malicious code on a hacked site goes into action. If this code loads other scripts upon a visit, the screen darkens and an apparently ordinary CAPTCHA appears. Instead of asking for human verification, the fake CAPTCHA instructs the user to open the Windows Run dialog and paste in a command — a command that can download and execute the attacker's malware.
A real CAPTCHA will never ask you to open the Windows Run dialog or paste commands. If any site — even one belonging to a small business — makes such a request, it is very likely a malware trap. With the initial point of compromise still unconfirmed, user vigilance is currently the only line of defense.
