Fake CAPTCHA ClickFix Drops Amatera via WebDAV

Cisco Talos · High sophistication
Last updated September 8, 2026

Cisco Talos investigated a real infection chain seen at a Ukrainian government organization where a disguised DLL was executed directly from a WebDAV network path. Attackers used a compromised website to show a fake Google CAPTCHA-style “verification” prompt that tricks users into running a copied command, which then downloads and executes the Amatera stealer and follow-on payloads (including NetSupport Manager). The campaign appears focused on stealing credentials and cryptocurrency data, with one branch assessed as linked to a Russian threat actor.

Key findings

  • Talos observed a real intrusion where a disguised DLL ("verification.google") executed from a WebDAV UNC path at a Ukrainian government organization.
  • A parallel chain ("pf.ch") was reconstructed and includes ClearFake JavaScript injected into a compromised site via a malicious Cloudflare Worker.
  • Victims are lured with a fake Google CAPTCHA-style ClickFix prompt that instructs them to open Windows Run and execute clipboard contents.
  • The ClickFix command opens a WebDAV path on a randomized subdomain of "leaguejazire[.]com" and executes the loader DLL via rundll32 ordinal execution.
  • Amatera stealer was the primary payload; secondary payloads differed by branch (ZigCryptoStealer + proxy in one branch; NetSupport Manager remote access tool in the other).
  • Talos tracks the actor behind the "verification.google" activity as UAT-10820 and assessed moderate confidence of a Russian threat actor for that branch.

Who’s being targeted

  • Commonly targeted roles: All employees, Executive leadership, Administrative staff, IT helpdesk / Service desk, SOC / Incident response, Users with access to financial accounts or crypto assets.
  • Affected industries: Government / Public Sector.
  • Attack channels: website.
  • Impersonated: Google CAPTCHA (fake verification prompt), Verification prompt (fake CAPTCHA-style check).

Awareness takeaways

  • Treat any ‘CAPTCHA’ or ‘verification’ that asks you to run a command (Windows Run or Terminal) as a scam and stop immediately.
  • Be cautious even on normal-looking websites, attackers can inject malicious code into compromised sites to trick employees.
  • Escalate suspicious ‘remote path’ or script-driven actions quickly, this chain used remote WebDAV locations to run disguised files.
  • Remote-access tools can be installed without approval as part of an intrusion; treat unexpected remote-control software as an incident.

Red flags to watch for

  • A CAPTCHA/verification prompt telling you to open Windows Run and paste a command is not normal.
  • The instruction results in running a command, not completing a web form.
  • The underlying action uses a remote WebDAV path and executes code (rundll32).
  • A website should not require pasting commands into Terminal.
  • Use of curl/command line for “verification” is highly suspicious.
  • The command contacts an unfamiliar domain/subdomain.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re browsing a normal site and a Google‑style CAPTCHA pops up: “Prove you’re human. Press Win+R and run this command.” That’s a real attack Cisco Talos saw: the fake CAPTCHA copies a command, you paste it into Windows Run, and it silently opens a WebDAV path on leaguejazire dot com to run a disguised DLL called verification.google, dropping the Amatera stealer and even NetSupport remote access. On macOS, the same trick tells you to open Terminal and paste a curl command to riyazinikokar dot xyz. Here’s the aha: real CAPTCHAs never ask you to use Windows Run or Terminal. If a “verification” needs a command line, it’s not verification, it’s malware delivery. If any CAPTCHA or “verification” tells you to open Windows Run or Terminal and paste a command, stop immediately and report it to Security, don’t run it, just screenshot it and send it in.

Categories

Similar attacks

ClickFix Trick Spreads ACR Stealer via Paste-Run

ClickFix Trick Spreads ACR Stealer via Paste-Run

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR (Amatera) Stealer. The malware steals saved browser passwords, live session tokens, and Microsoft 365/OneDrive/SharePoint files, meaning…

July 17, 2026
TELEPUZ Spreads via ClickFix “Fix” Web Lures

TELEPUZ Spreads via ClickFix “Fix” Web Lures

Researchers report a real, active malware operation where compromised websites use “ClickFix” style prompts to trick people into manually pasting and running malicious commands. The result is a multi-stage infection that downloads additional payloads and ultimately runs TELEPUZ, which can steal…

July 16, 2026
Fake IT Support on Teams Drops TWINLOOT

Fake IT Support on Teams Drops TWINLOOT

Researchers observed an active campaign where attackers used Microsoft Teams to impersonate IT support and trick a user into running a PowerShell command. That action downloaded a malicious package that enabled credential theft (via a fake lock screen) and helped attackers move through internal…

August 18, 2026
Sandworm Uses Fake CAPTCHAs to Spread Malware

Sandworm Uses Fake CAPTCHAs to Spread Malware

Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA checks. Victims are instructed to copy and paste a PowerShell command, which downloads malware and can lead to deeper compromise. CERT also…

July 16, 2026
TerminalFix Fake CAPTCHA Tricks Users Into PowerShell

TerminalFix Fake CAPTCHA Tricks Users Into PowerShell

Microsoft reported a real-world campaign (“TerminalFix”) where attackers use compromised websites to show a fake Cloudflare CAPTCHA. The prompt tricks visitors into copying and running a malicious PowerShell/Terminal command, which then installs a reverse-tunnel backdoor that can give attackers…

August 30, 2026
Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

Fake CAPTCHA ‘ClickFix’ Drops Cruciferra Malware

A real malware campaign used compromised websites to show fake CAPTCHA/verification pages that tricked people into copying and running a PowerShell command themselves. That manual “copy/paste” step helped the attackers bypass normal download defenses and install the Cruciferra loader, which then…

August 25, 2026