Bitcoin Forum
December 29, 2025, 04:56:31 PM *
News: Latest Bitcoin Core release: 30.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: New tactic for spreading malwares: Fake CAPTCHA verification  (Read 106 times)
Forsyth Jones (OP)
Legendary
*
Offline Offline

Activity: 1764
Merit: 1886


I love Bitcoin!


View Profile WWW
April 20, 2025, 09:06:09 PM
Merited by vapourminer (1)
 #1

Be careful with fake CAPTCHA verifications. Hackers are using this new method to install malware like clipboard hijacking or other malicious software to steal personal data and mainly BTC/Crypto from users.

The attack consists of the victim visiting a malicious site or one hijacked by malicious agents. They are asked to complete a normal CAPTCHA verification (like any site that uses CAPTCHA). However, after this, the victim is tricked into executing a command in Windows' Run, claiming it's a final verification step. The command is then copied to the clipboard without the victim noticing. In reality, it's a wget command to download malware onto victims' computers.



Recently, I visited a site infected with the fake CAPTCHA spreading malware. I posted about it on altcoinstalks. I wasn't a victim of this attack because I immediately recognized it as a malware attempt.

While these instructions may seem harmless enough, if you follow the steps you will actually be infecting yourself with malware—most likely an information stealer. In the background, the website you visited copied a command to your clipboard. In Chromium based browsers (which are almost all the popular ones) a website can only write to your clipboard with your permission. But Windows was under the assumption that you agreed to that when you checked the checkbox in the first screen.

What the obstructions in the prompt are telling you to do is:

1 - Open the Run dialog box on Windows.
2 - Paste the content of your clipboard into that dialog box.
3 - Execute the command you just pasted.
They are not lying about what you will “observe”, but what they don’t tell you is that that’s only the last part of what you pasted, and what you are seeing is not really part of the command but just a comment added behind it.

But under normal circumstances, this is what will be visible.

After doing some research, I found a study by Malwarebytes anti-malware highlighting this deceptive tactic and providing tips on simple measures to counteract this type of attack: https://www.malwarebytes.com/blog/news/2025/03/fake-captcha-websites-hijack-your-clipboard-to-install-information-stealers

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
Outhue
Hero Member
*****
Offline Offline

Activity: 1428
Merit: 625



View Profile WWW
April 21, 2025, 11:45:50 AM
 #2

This was how my cousin lost a lot of money on his PC in 2021, it was a clipboard malware attack, it looks obviously like a scam because that's not how a real captcha looks like, you are to select some images to match a image, it is always image related.

Every attacks been carried out on PC starts with the user themselves, they are been asked for permission and the user give them without realising it, the three available option on the image that OP dropped are all the same attack.

I know that I am still learning but I am not ready to learn the hard way while losing assets to hackers again, since the day I get my hardware wallet I don't need to worry about any attacks on PC, if you are still a user always be on the watch out.

Hackers and scammers don't rest until the find their victims.

▄▄█████████████████▄▄
▄█████████████████████▄
███▀▀█████▀▀░░▀▀███████

██▄░░▀▀░░▄▄██▄░░█████
█████░░░████████░░█████
████▌░▄░░█████▀░░██████
███▌░▐█▌░░▀▀▀▀░░▄██████
███░░▌██░░▄░░▄█████████
███▌░▀▄▀░░█▄░░█████████
████▄░░░▄███▄░░▀▀█▀▀███
██████████████▄▄░░░▄███
▀█████████████████████▀
▀▀█████████████████▀▀
..Rainbet.com..
CRYPTO CASINO & SPORTSBOOK
|
█▄█▄█▄███████▄█▄█▄█
███████████████████
███████████████████
███████████████████
█████▀█▀▀▄▄▄▀██████
█████▀▄▀████░██████
█████░██░█▀▄███████
████▄▀▀▄▄▀███████
█████████▄▀▄██
█████████████████
███████████████████
██████████████████
███████████████████
 
 $20,000 
WEEKLY RAFFLE
|



█████████
█████████ ██
▄▄█░▄░▄█▄░▄░█▄▄
▀██░▐█████▌░██▀
▄█▄░▀▀▀▀▀░▄█▄
▀▀▀█▄▄░▄▄█▀▀▀
▀█▀░▀█▀
10K
WEEKLY
RACE
100K
MONTHLY
RACE
|

██









█████
███████
███████
█▄
██████
████▄▄
█████████████▄
███████████████▄
░▄████████████████▄
▄██████████████████▄
███████████████▀████
██████████▀██████████
██████████████████
░█████████████████▀
░░▀███████████████▀
████▀▀███
███████▀▀
████████████████████   ██
 
..►PLAY...
 
████████   ██████████████
Porfirii
Legendary
*
Offline Offline

Activity: 2380
Merit: 3318


The Alliance Of Bitcointalk Translators - ENG>SPA


View Profile WWW
April 21, 2025, 11:53:44 AM
 #3

Thanks for sharing this new attack with us Forsyth Jones! (not so new as Outhue mentioned it has been around since at least 2021, but still new for me).

I heard of clipboard malware before, of course, but not of attacks like that which use the excuse of a Captcha verification! and I think that it's the typical attack that can catch you off guard, because it's not uncommon for these captcha checks to change from time to time.

From now on I will absolutely doubt everything that deviates from what I know, just in case Undecided

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
Taskford
Legendary
*
Offline Offline

Activity: 3122
Merit: 1000


Top-tier crypto casino and sportsbook


View Profile
April 21, 2025, 01:00:48 PM
 #4

Thanks for sharing this new attack with us Forsyth Jones! (not so new as Outhue mentioned it has been around since at least 2021, but still new for me).

I heard of clipboard malware before, of course, but not of attacks like that which use the excuse of a Captcha verification! and I think that it's the typical attack that can catch you off guard, because it's not uncommon for these captcha checks to change from time to time.

From now on I will absolutely doubt everything that deviates from what I know, just in case Undecided

That malware embedded on captcha is I think the latest attempt done by those hackers. If we are not really aware of it then provably that we might get caught up by this thing. Its unnoticeable when they do that especially that lots of site needs to do captcha before you can log in on their site and lots of people might fall for that especially if they are not paying attention on what they are doing.

I guess much better for people to Norton Antivirus Plus and Bitfender Antivirus since I think this two have malware detection.

We really need to be suspicious on things unusual to us and also always check our wallet address copied so that we can avoid getting a problem with this malwares.

██████▄██▄███████████▄█▄
█████▄█████▄████▄▄▄█
███████████████████
████▐███████████████████
███████████▀▀▄▄▄▄███████
██▄███████▄▀███▀█▀▀█▄▄▄█
▀██████████▄█████▄▄█████▀██
██████████▄████▀██▄▀▀▀█████▄
█████████████▐█▄▀▄███▀██▄
███████▄▄▄███▌▌█▄▀▀███████▄
▀▀▀███████████▌██▀▀▀▀▀█▄▄▄████▀
███████▀▀██████▄▄██▄▄▄▄███▀▀
████████████▀▀▀██████████
 BETFURY ....█████████████
███████████████
███████████████
██▀▀▀▀█▀▀▄░▄███
█▄░░░░░██▌▐████
█████▌▐██▌▐████
███▀▀░▀█▀░░▀███
██░▄▀░█░▄▀░░░██
██░░░░█░░░░░░██
███▄░░▄█▄░░▄███
███████████████
███████████████
░░█████████████
█████████████
███████████████
███████████████
██▀▄▄▄▄▄▄▄▄████
██░█▀░░░░░░░▀██
██░█░▀░▄░▄░░░██
██░█░░█████░░██
██░█░░▀███▀░░██
██░█░░░░▀░░▄░██
████▄░░░░░░░▄██
███████████████
███████████████
░░█████████████
LogitechMouse
Legendary
*
Offline Offline

Activity: 3038
Merit: 1101


Need a Marketing Manager? |Telegram ID- @LT_Mouse


View Profile WWW
April 21, 2025, 01:27:26 PM
 #5

It's my first time to see this kind of tactic by these hackers. Thanks for sharing OP.

I guess it's time for us to read whatever is popping out especially if it's our first time to visit that website. I'm reading OP's post and thinking if I will be a victim of this one even though I haven't read this post, and I think I will still not be a victim, for some reasons. Maybe the fact that I read everything especially if it's my first time visiting that website is my reason why I don't think I'll be a victim of it although I'm afraid that those who are just clicking, and clicking, and doing what they're seeing on their screen will just be the easiest targets for these scammers.

Being ignorant nowadays really is very hard and we must equipped ourselves with knowledge first. Newbies are the hackers' primary targets. Having an anti-virus at least can help with this one (I don't know if Microsoft Defense is enough), but always, always read everything, and don't just click, and click blindly.

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
Forsyth Jones (OP)
Legendary
*
Offline Offline

Activity: 1764
Merit: 1886


I love Bitcoin!


View Profile WWW
April 21, 2025, 01:31:52 PM
Merited by vapourminer (1)
 #6

...
I know that I am still learning but I am not ready to learn the hard way while losing assets to hackers again, since the day I get my hardware wallet I don't need to worry about any attacks on PC, if you are still a user always be on the watch out.

Hackers and scammers don't rest until the find their victims.
I emphasize the importance of always checking the sending address, at least the first and last 4 digits of an address, because even if you use hardware wallets, you are susceptible to this attack, so always check all the details of the transaction on the display of your signing device.

Always match the sending address with the sender, from where the address was copied, scan the address via QR code if possible, to avoid using the clipboard, which can be attacked if the machine has this malware.

If you are about to send a significant amount of funds and still feel uncomfortable, send a small fraction first to make sure everything is in order and then send the remaining funds, while carefully checking all characters of the destination address.

This is one of the only ways to have your funds stolen even with hardware wallets through social engineering.

Thanks for sharing this new attack with us Forsyth Jones! (not so new as Outhue mentioned it has been around since at least 2021, but still new for me).

I heard of clipboard malware before, of course, but not of attacks like that which use the excuse of a Captcha verification! and I think that it's the typical attack that can catch you off guard, because it's not uncommon for these captcha checks to change from time to time.

From now on I will absolutely doubt everything that deviates from what I know, just in case Undecided
...
That malware embedded on captcha is I think the latest attempt done by those hackers. If we are not really aware of it then provably that we might get caught up by this thing. Its unnoticeable when they do that especially that lots of site needs to do captcha before you can log in on their site and lots of people might fall for that especially if they are not paying attention on what they are doing.
...

Do you think clipboard hijacking malware can be compared to the category of spyware? Since he is waiting for an address to be copied to exchange for the scammers' registered addresses?

...
I guess it's time for us to read whatever is popping out especially if it's our first time to visit that website. I'm reading OP's post and thinking if I will be a victim of this one even though I haven't read this post, and I think I will still not be a victim, for some reasons. Maybe the fact that I read everything especially if it's my first time visiting that website is my reason why I don't think I'll be a victim of it although I'm afraid that those who are just clicking, and clicking, and doing what they're seeing on their screen will just be the easiest targets for these scammers.
...
Often, due to rush and anxiety, people speed through steps clicking OK,Next... and end up leaving security gaps in their computer without even realizing it. Haste is the enemy of perfection.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
rdluffy
Legendary
*
Offline Offline

Activity: 2828
Merit: 1857



View Profile WWW
April 21, 2025, 01:45:34 PM
 #7

I emphasize the importance of always checking the sending address, at least the first and last 4 digits of an address, because even if you use hardware wallets, you are susceptible to this attack, so always check all the details of the transaction on the display of your signing device.

I don't remember now where I read it, but it was about a possible scam attempt where the hackers had many wallets generated and so the user used Copy and Paste, and when he pasted the address, it was the hackers'
So far it's the usual scam
However, with the huge number of addresses, the address that the user pasted was as similar as possible to the first and last digits of the user's original address

In some larger transactions I always check almost the entire address so that there is no margin for error




I've never come across this Captcha, but it's always good to spread the message to inform as many people as possible
A lay user could fall for this scam easily

 
.Winna.com..

░░░░░░░▄▀▀▀
░░


▐▌▐▌
▄▄▄▒▒▒▄▄▄
████████████
█████████████
███▀▀███▀

▄▄

██████████████
████████████▄
█████████████
███▄███▄█████▌
███▀▀█▀▀█████
████▀▀▀█████▌
████████████
█████████████
█████
▀▀▀██████

▄▄
THE ULTIMATE CRYPTO
...CASINO & SPORTSBOOK...
─────  ♦  ─────

▄▄██▄▄
▄▄████████▄▄
██████████████
████████████████
███████████████
████████████████
▀██████████████▀
▀██████████▀
▀████▀

▄▄▄▄

▄▄▀███▀▄▄
▄██████████▄
███████████
███▄▄
▄███▄▄▄███
████▀█████▀███
█████████████████
█████████████
▀███████████
▀▀█████▀▀

▄▄▄▄


.....INSTANT.....
WITHDRAWALS
 
...UP TO 30%...
LOSSBACK
 
 

   PLAY NOW   
DYING_S0UL
Hero Member
*****
Offline Offline

Activity: 896
Merit: 883


The Alliance Of Bitcointalk Translators - ENG>BAN


View Profile WWW
April 21, 2025, 04:15:03 PM
 #8

Even though it seems like this malware has been around for quite some times but to be honest the method the hackers are pulling seems a little stupid. I mean what if you were a mobile user or a mac user, lol..people might be thinking what the fuck! I don't have any windows keys! Not trying to make fun, or mock others, but literally who falls for scams such as this are dumbwitted. I wonder how many would actually fall for this scam.

Anyway thank you for sharing this, I'm sure many newbies would be careful after reading this..

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
DediRock
Newbie
*
Offline Offline

Activity: 179
Merit: 0


View Profile WWW
April 21, 2025, 05:07:58 PM
 #9

Thanks for sharing this. More people need to know how subtle these attacks can be.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!