Fake CAPTCHA Trick Fuels WebDAV Malware Chain

Cisco Talos · Medium sophistication
Last updated September 11, 2026

Cisco Talos investigated a real incident at a Ukrainian government organization and found a complex WebDAV-based infection chain linked to a Russian actor (UAT-10820). The campaign uses fake CAPTCHA/verification prompts to manipulate users into copying and pasting commands, leading to credential and cryptocurrency theft and additional remote-access tools.

How the attack worked

Cisco Talos investigated an incident at a Ukrainian government organization and uncovered what it described as a complex WebDAV infection chain. The activity is attributed to a Russian actor tracked as UAT-10820. Rather than relying on a malicious attachment or link alone, the campaign used a fake CAPTCHA or human-verification prompt on a website to manipulate users into copying and pasting a command into their own system. That single action kicked off the infection chain, ultimately delivering Amatera stealer, ZigCryptoStealer, and NetSupport Manager, along with a vulnerable driver capable of terminating EDR software and additional unauthorized remote access tools.

Why it succeeded

The technique worked because it exploited a familiar, low-friction interaction: verifying you are human on a website. Most users have been trained to click a checkbox or solve a simple puzzle for CAPTCHA checks, not to run commands. By dressing up the request as a routine verification step, attackers bypassed the skepticism that a more obviously suspicious email or download prompt might trigger. The campaign also abused legitimate infrastructure, such as the BNB Smart Chain for bulletproof hosting, which helped the malicious activity blend in and evade traditional web filters.

What to watch for

  • A CAPTCHA or verification prompt that asks you to copy and paste a command rather than click a box or solve a puzzle
  • Any website step that asks you to open a terminal, run a program, or paste text into your operating system to "continue"
  • Pushy or unusual instructions framed as bypassing normal browser protections
  • Unexpected remote access tools or software appearing on a system after visiting a site

Building resistance

Organizations, especially those in government and other sectors targeted by this kind of activity, should reinforce a simple rule: legitimate verification steps never require pasting commands into your computer. Awareness training should specifically call out this pattern, since it does not look like a typical phishing email and can catch users off guard on otherwise normal-looking websites.

Key takeaways for defenders:

  • Train all employees, administrative staff, IT support, and security operations teams to recognize fake verification prompts as a distinct social engineering pattern
  • Encourage users to report unexpected "human verification" steps to IT or security rather than following them
  • Remind staff that attackers may use legitimate-looking platforms and infrastructure to make malicious activity appear trustworthy
  • Pair this awareness with technical controls, since the campaign also involved tools designed to disable endpoint defenses once execution succeeds

This incident is a reminder that social engineering keeps evolving beyond email, and that browser-based interactions deserve the same scrutiny as suspicious messages.

Key findings

  • Talos investigated an incident at a Ukrainian government organization and found a “complex WebDAV infection chain.”
  • The activity is attributed to a Russian actor tracked as “UAT-10820.”
  • The campaign uses “fake CAPTCHA prompts” and tricks users into “copying and pasting commands from fake verification prompts.”
  • Malware delivered includes “Amatera stealer” plus “ZigCryptoStealer and NetSupport Manager.”
  • Secondary capabilities include “a vulnerable driver to terminate EDR software” and “unauthorized remote access tools.”

Who’s being targeted

  • Commonly targeted roles: All employees, Administrative staff, IT support/helpdesk, Security operations.
  • Affected industries: Government.
  • Attack channels: website.
  • Impersonated: Website verification (CAPTCHA) prompt.

Red flags to watch for

  • A CAPTCHA/verification prompt asking you to copy/paste commands
  • Unexpected technical steps to “verify” you are human
  • Pushy instructions to bypass normal browser protections
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the fake CAPTCHA attack technique?

Attackers show a fake human-verification prompt that instructs the user to copy and paste a command to continue, which actually runs malicious code on their machine.

What malware was delivered in this campaign?

The chain delivered Amatera stealer, ZigCryptoStealer, and NetSupport Manager, along with a vulnerable driver used to terminate EDR software and additional remote access tools.

Who was targeted in this attack?

Cisco Talos investigated an incident at a Ukrainian government organization, with the activity attributed to a Russian actor tracked as UAT-10820.

How can organizations train users to spot this attack?

Teach staff that legitimate CAPTCHA checks never require copying and pasting commands, and encourage reporting of unexpected verification steps to IT or security teams.

Read the video transcript

Imagine a website says, "I’m not a robot: Verification required. Please copy and paste this command to continue." That one step can hand over your passwords and crypto. Cisco Talos saw this for real at a Ukrainian government site: a complex WebDAV infection chain tied to a group called UAT-10820. The fake CAPTCHA gets you to run their command, which quietly pulls down tools like Amatera stealer, ZigCryptoStealer, and NetSupport Manager. Here’s the nasty part: once that runs, it can steal your credentials and crypto, use a vulnerable driver to kill EDR, and give remote access to your machine. They even hide behind legit platforms like the BNB Smart Chain so web filters don’t block it. Aha rule: real CAPTCHAs never ask you to copy and paste commands. If any website does that, stop, close the tab, and report it to IT or security right away.

Categories

Similar attacks

Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Real-Time Smishing Tool Steals 2FA Codes Live

Real-Time Smishing Tool Steals 2FA Codes Live

Cisco Talos reported a real-time phishing framework called “JWR” that guides victims through fake checkout and login pages while attackers watch keystrokes live. It is being delivered through SMS messages that impersonate toll and postal authorities, and it can capture payment details, identity…

August 13, 2026
Bank Impersonation Phish Pushes Remote Tool

Bank Impersonation Phish Pushes Remote Tool

A real, active phishing campaign impersonating Bank of America tricks victims into downloading a fake “Account Guard” that installs ScreenConnect remote access on Windows, while Mac users are redirected to a credential-stealing page asking for banking and identity details. Separately, Microsoft…

August 6, 2026
Greatness PhaaS Adds Device-Code MFA Bypass

Greatness PhaaS Adds Device-Code MFA Bypass

Criminals using the “Greatness” phishing-as-a-service kit are running real-world phishing campaigns that trick employees into approving a Microsoft device-code login flow, allowing attackers to bypass MFA and steal access tokens. Recent activity includes RingCentral “voicemail” lures and multi-step…

August 4, 2026
Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026