
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
Threat actors are using fake CAPTCHA pages on compromised or lookalike websites to trick people into copying and pasting malicious commands (“paste and run”). The article describes real campaigns tied to CastleLoader and similar activity, including fake background-removal sites and job-site impersonation domains promoted via Google Ads.
This campaign relies on fake verification pages that mimic ordinary CAPTCHA or Cloudflare Turnstile checks. Instead of clicking a checkbox or solving an image puzzle, victims are told to copy a piece of text and paste it into the Windows Run dialog or a command prompt to prove they are human. That pasted text is actually a malicious command. In one version, users visiting fake background-removal tools like ai-scan[.]digital and bg-transparency[.]online were shown a non-functional interface with upload progress bars before being prompted to complete the fake CAPTCHA. In another version, typosquatted job-site domains such as linkedall[.]org, golinked[.]net, and indeed-jobs[.]net were promoted through Google Ads and led users to fake Cloudflare Turnstile pages that triggered the same infection chain. Both paths were observed distributing CastleLoader, a malware loader capable of delivering infostealers and remote access tools.
The lure works because it borrows the visual language of routine, low-friction security checks that people encounter constantly online. A CAPTCHA feels procedural and harmless, so asking someone to paste a short snippet of text does not immediately register as dangerous. The job-site impersonation angle adds urgency and plausibility for people actively searching for work, while paid search ads lend the fake domains an appearance of legitimacy before a user even lands on the page.
Organizations can reduce risk by training employees on a simple rule: never paste content from a website into the Run box, terminal, or command prompt. Employees should also be encouraged to check the actual domain name before interacting with a site reached through a search ad, and to treat unexpected security checks with skepticism. Establishing a clear, low-friction way for staff to report suspicious sites or unusual verification prompts to security teams gives people an easy off-ramp instead of following through on a risky instruction.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a social engineering technique where a fake website, such as a bogus CAPTCHA or verification page, tricks a user into copying a malicious command and pasting it into the Run dialog or command prompt, which then executes attacker code.
CastleLoader has been distributed through fake background-removal websites and through job platform impersonation campaigns using typosquatted domains promoted via Google Ads.
Red flags include a site asking you to copy and paste a command to verify you are human, a non-functional interface with only progress bars, and pasted text that resembles a command line instruction rather than a normal CAPTCHA check.
All employees are potential targets, but the campaigns specifically call out recruiting/HR staff, marketing/design teams, job seekers, and anyone browsing the web, since one lure impersonates job platforms and another impersonates background-removal tools.
You land on a background-removal site, upload a photo, and a CAPTCHA says: copy this command to prove you’re human. This is a paste-and-run scam pushing CastleLoader. Fake sites like ai-scan.digital or bg-transparency.online use a bogus CAPTCHA to copy a command with carets and finger.exe, then tell you to run it. Same trick on job sites: Google Ads send you to linkedall.org or indeed-jobs.net with a fake Cloudflare Turnstile. Instead of a checkbox, it tells you to paste a command into Run or Command Prompt. A real CAPTCHA never makes you copy commands. If any site tells you to paste something into Run, Terminal, or Command Prompt, stop immediately and report it to security.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because…

Attackers compromised hundreds of legitimate websites and injected code that sent visitors to a fake Cloudflare page. The fake page used a “ClickFix” trick to…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Researchers say a North Korea-aligned group is targeting Web3 and crypto professionals with fake recruiter outreach and “mandatory” online skill tests. During…