Security Stop-Press: Fake CAPTCHAs Used To Trick Users Into Installing Malware

Written by Pronetic

Pronetic is a leading provider of core IT support for ISO 27001, Cyber Essentials and Cyber Essentials Plus compliance.

March 26, 2025

Cybercriminals are exploiting users’ trust in familiar verification tools like CAPTCHAs to trick them into infecting their own systems, according to HP Wolf Security’s latest Threat Insights Report.

The report highlights a rise in social engineering campaigns built around a fake CAPTCHA page where users are lured into completing bogus verification steps, exploiting what HP terms “click tolerance”, a habit of blindly following prompts due to frequent exposure to login and security checks.

Victims are directed to attacker-controlled websites where clicking “I’m not a robot” secretly copies a malicious PowerShell command to their clipboard. They are then instructed to open the Windows Run prompt, paste the code, and execute it, thereby unknowingly launching a malware infection themselves.

The primary payload, Lumma Stealer, is a powerful information-stealing tool capable of grabbing credentials and crypto wallets. The malware is hidden in a disguised ZIP archive and deployed using DLL sideloading to avoid detection.

HP reports that these campaigns often use reputable cloud services to host the malicious content, helping them bypass web filters and email gateways. Victims are typically drawn in via search engine hijacking, ads, or compromised websites.

To stay protected, businesses should disable clipboard sharing and restrict access to the Windows Run command where possible. Regular training can also help staff recognise and resist deceptive prompts.

You May Also Like…

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Why Choose Pronetic

We Are ISO 27001 & Cyber Essentials Plus Certified

Be reassured that we have been externally audited. You can have complete peace of mind that the team managing your IT systems and safeguarding your data are independently vetted annually.

Seamless & Comprehensive IT Support

Our investment in people, tools and processes, continuously improved, ensures that we don’t just deliver exceptional I.T. support but include your compliance to Cyber Essentials or ISO 27001 “baked-in”. Yes, that means no more annual headaches and stress when your certification comes round.

Expert Support Money Back Guarantee

We're confident in the value we deliver. That's why we offer a 90-day, no-quibble money-back guarantee. If, for any reason, you're not completely satisfied with our IT support services, we'll provide a full refund and cancel your contract without any hassle.

Book Your Free IT Strategy Call Now!

Simply Fill In The Form Below To Receive Your Free IT Strategy Call:

By submitting this form, you consent to us using your personal information to contact you. For more information please see our privacy policy.