Cyberattackers Embrace CAPTCHAs to Hide Phishing, Malware
#1
Information 
Quote:Cyberattackers are using Google’s reCAPTCHA (aka the “I am not a robot” function) and fake CAPTCHA-like services to obscure various phishing and other campaigns, according to researchers. There are signs however that those evasion efforts may be losing their efficacy.
 
CAPTCHAs are familiar to most internet users as the challenges that are used to confirm that they’re human. The Turing test-ish puzzles usually involve clicking all photos in a grid that contain a certain object, or typing in a word presented as blurred or distorted text.
 
The idea is to weed out bots on eCommerce and online account sites – and they serve the same purpose for crooks.
 
“Hiding phishing content behind CAPTCHAs prevents security crawlers from detecting malicious content and adds a legitimate look to phishing login pages,” according to a Friday writeup from Palo Alto Networks’ Unit 42.
 
Though it’s far from new, it’s an increasingly popular technique: Just in the last month, the firm found 7,572 unique malicious URLs over 4,088 pay-level domains employing the obfuscation method. That’s an average of 529 new CAPTCHA-protected malicious URLs per day.

Read more: Cyberattackers Embrace CAPTCHAs to Hide Phishing, Malware
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
uBOLite 2026.621.2046
uBOLite 2026.621.2...harlan4096 — 09:27
Microsoft confirms Windows 11 version 2...
Microsoft Confirms W...harlan4096 — 08:41
AxCrypt 3.1.5.0
AxCrypt 3.1.5.0: ...harlan4096 — 11:50
AMD will reinstate memory encryption on ...
The feature was qu...harlan4096 — 11:48
Microsoft confirms Windows 11 version 26...
Who would have gue...harlan4096 — 11:46

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>