Skip to main content

Sneaky malware abuses CAPTCHA to bypass browser protections

cybersecurity
(Image credit: Shutterstock)

Cybersecurity experts have shared details about a novel malware campaign that bypasses browser warnings by tricking users into complying with a fake CAPTCHA challenge.

The security researchers known as the MalwareHunterTeam provided BleepingComputer with a suspicious-looking URL, which takes victims to a webpage that includes an embedded YouTube video. 

As soon as the victims hit the Play button, the webpage downloads an executable named console-play.exe, which it camouflages behind a fake CAPTCHA challenge.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Decoding the trickery, BleepingComputer reveals that the fake CAPTCHA gets the victims to press the right keys to overrule the browser’s suspicions about the executable file, enabling the malicious file to download the malware onto the computer.

Captcha trickery

Since the file that the Play button asks the browser to download is an executable, virtually all modern web browsers will display a prompt asking the users to confirm the action. 

To bypass this warning, the scam brings up the fake CAPTCHA challenge, which prompts the user to enter a series of keys. Embedded within the list of keys to be pressed is the Tab key and the Enter key.

The Tab key will change the focus of the browser’s prompt to ignore the warning, and the Enter key will confirm the choice and download the file. 

Once the malicious executable is on your computer it will jump through hoops before downloading the Gozi/Ursnif banking trojan, which will then get to its nefarious purposes and steal account credentials and further infect the computer by pulling in more malware.

Notably, this is the second scam in as many weeks that has capitalized on internet users’ trust in CAPTCHA challenges to manipulate victims.

Via BleepingComputer

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.