Site navigation

‘I Am Not a Robot’ CAPTCHAs Being Used to Spread Malware, HP Warns

Graham Turner

,

Fake CAPTCHA attacks
HP launches its latest Threat Insights Report highlighting real-world threats uncovered by HP Wolf Security researchers.

At it’s annual Amplify Conference, HP Inc. issued its latest Threat Insights Report, highlighting rising usage of fake CAPTCHA verification tests which allow threat actors to trick users into infecting themselves. The campaigns show attackers are capitalising on growing click tolerance, whereby users are now accustomed to jumping through hoops to authenticate themselves online.

With analysis of real-world cyber-attacks, the report seeks to help organisations to keep up with the latest techniques cyber-criminals are using to evade detection and breach PCs.

Below – and based on data from millions of endpoints running HP Wolf Security – we’ll look at three notable campaigns identified by HP threat researchers include

CAPTCHA Me If You Can

As bots get better at bypassing CAPTCHAs, authentication has grown more elaborate – meaning users have become more accustomed to jumping through hoops to prove they are human.

HP threat researchers identified multiple campaigns where attackers crafted malicious CAPTCHAs.

Users were directed to attacker-controlled sites, and prompted to complete a range of fake authentication challenges. Victims were tricked into running a malicious PowerShell command on their PC that ultimately installed the Lumma Stealer remote access trojan (RAT).

Attackers Capable of Accessing End-Users’ Webcams and Microphones to Spy on Victims

A second campaign saw attackers spreading an open source RAT, XenoRAT, with advanced surveillance features such as microphone and webcam capture.

Using social engineering techniques to convince users to enable macros in Word and Excel documents, attackers could control devices, exfiltrate data, and log keystrokes – showing Word and Excel still present a risk for malware deployment.

Python Scripts Used for SVG Smuggling

Another notable campaign shows how attackers are delivering malicious JavaScript code inside Scalable Vector Graphic (SVG) images to evade detection.

These images are opened by default in web browsers and execute the embedded code to deploy seven payloads—including RATs and infostealers—offering redundancy and monetization opportunities for the attacker. As part of the infection chain the attackers also used obfuscated Python scripts to install the malware.


Recommended reading


Python’s popularity – which is being further boosted by rising interest in AI and data science – means it is an increasingly attractive language for attackers to write malware, as its interpreter is widely installed.

Patrick Schläpfer, principal threat researcher in the HP Security Lab, comments:  “A common thread across these campaigns is the use of obfuscation and anti-analysis techniques to slow down investigations. Even simple but effective defence evasion techniques can delay the detection and response of security operations teams, making it harder to contain an intrusion.

“By using methods like direct system calls, attackers make it tougher for security tools to catch malicious activity, giving them more time to operate undetected – and compromise victims endpoints.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data