Attackers Compromise 5,400 Small-Business Sites to Push Malware as Fake CAPTCHAs Trigger Windows Commands
Updated
Updated · Fox News · Sep 13
Attackers Compromise 5,400 Small-Business Sites to Push Malware as Fake CAPTCHAs Trigger Windows Commands
1 articles · Updated · Fox News · Sep 13
Summary
Netskope found more than 5,400 compromised websites across 2,200 organizations, with several hundred active on a given day and over 300 contacting malicious infrastructure each weekday.
The attack hits legitimate small-business sites, where hidden code blurs the page and shows a fake CAPTCHA that tells Windows users to open Run and paste a command that downloads malware.
Researchers say the campaign relies on ClickFix social engineering rather than a browser exploit, exploiting trust in familiar CAPTCHA prompts on real clinic, plumbing, retail and other local business websites.
Attackers are storing instructions on the BNB Smart Chain test network, making the infrastructure cheaper and harder to disrupt, and Netskope also saw a newer WebRTC-based variant that can deliver code directly through the browser.
The key warning sign is simple: a real CAPTCHA should never ask users to open Windows Run, PowerShell or Command Prompt, while site owners are being urged to check CMS files and update WordPress, PrestaShop and plugins.