Cisco Talos investigated a real incident at a Ukrainian government organization and found a complex WebDAV-based infection chain linked to a Russian actor (UAT-10820). The campaign uses fake CAPTCHA/verification prompts to manipulate users into copying and pasting commands, leading to credential and cryptocurrency theft and additional remote-access tools.
How the attack worked
Cisco Talos investigated an incident at a Ukrainian government organization and uncovered what it described as a complex WebDAV infection chain. The activity is attributed to a Russian actor tracked as UAT-10820. Rather than relying on a malicious attachment or link alone, the campaign used a fake CAPTCHA or human-verification prompt on a website to manipulate users into copying and pasting a command into their own system. That single action kicked off the infection chain, ultimately delivering Amatera stealer, ZigCryptoStealer, and NetSupport Manager, along with a vulnerable driver capable of terminating EDR software and additional unauthorized remote access tools.
Why it succeeded
The technique worked because it exploited a familiar, low-friction interaction: verifying you are human on a website. Most users have been trained to click a checkbox or solve a simple puzzle for CAPTCHA checks, not to run commands. By dressing up the request as a routine verification step, attackers bypassed the skepticism that a more obviously suspicious email or download prompt might trigger. The campaign also abused legitimate infrastructure, such as the BNB Smart Chain for bulletproof hosting, which helped the malicious activity blend in and evade traditional web filters.
What to watch for
- A CAPTCHA or verification prompt that asks you to copy and paste a command rather than click a box or solve a puzzle
- Any website step that asks you to open a terminal, run a program, or paste text into your operating system to "continue"
- Pushy or unusual instructions framed as bypassing normal browser protections
- Unexpected remote access tools or software appearing on a system after visiting a site
Building resistance
Organizations, especially those in government and other sectors targeted by this kind of activity, should reinforce a simple rule: legitimate verification steps never require pasting commands into your computer. Awareness training should specifically call out this pattern, since it does not look like a typical phishing email and can catch users off guard on otherwise normal-looking websites.
Key takeaways for defenders:
- Train all employees, administrative staff, IT support, and security operations teams to recognize fake verification prompts as a distinct social engineering pattern
- Encourage users to report unexpected "human verification" steps to IT or security rather than following them
- Remind staff that attackers may use legitimate-looking platforms and infrastructure to make malicious activity appear trustworthy
- Pair this awareness with technical controls, since the campaign also involved tools designed to disable endpoint defenses once execution succeeds
This incident is a reminder that social engineering keeps evolving beyond email, and that browser-based interactions deserve the same scrutiny as suspicious messages.
Key findings
- Talos investigated an incident at a Ukrainian government organization and found a “complex WebDAV infection chain.”
- The activity is attributed to a Russian actor tracked as “UAT-10820.”
- The campaign uses “fake CAPTCHA prompts” and tricks users into “copying and pasting commands from fake verification prompts.”
- Malware delivered includes “Amatera stealer” plus “ZigCryptoStealer and NetSupport Manager.”
- Secondary capabilities include “a vulnerable driver to terminate EDR software” and “unauthorized remote access tools.”
Who’s being targeted
- Commonly targeted roles: All employees, Administrative staff, IT support/helpdesk, Security operations.
- Affected industries: Government.
- Attack channels: website.
- Impersonated: Website verification (CAPTCHA) prompt.
Red flags to watch for
- A CAPTCHA/verification prompt asking you to copy/paste commands
- Unexpected technical steps to “verify” you are human
- Pushy instructions to bypass normal browser protections
Frequently asked questions
What is the fake CAPTCHA attack technique?
Attackers show a fake human-verification prompt that instructs the user to copy and paste a command to continue, which actually runs malicious code on their machine.
What malware was delivered in this campaign?
The chain delivered Amatera stealer, ZigCryptoStealer, and NetSupport Manager, along with a vulnerable driver used to terminate EDR software and additional remote access tools.
Who was targeted in this attack?
Cisco Talos investigated an incident at a Ukrainian government organization, with the activity attributed to a Russian actor tracked as UAT-10820.
How can organizations train users to spot this attack?
Teach staff that legitimate CAPTCHA checks never require copying and pasting commands, and encourage reporting of unexpected verification steps to IT or security teams.
Read the video transcript
Imagine a website says, "I’m not a robot: Verification required. Please copy and paste this command to continue." That one step can hand over your passwords and crypto. Cisco Talos saw this for real at a Ukrainian government site: a complex WebDAV infection chain tied to a group called UAT-10820. The fake CAPTCHA gets you to run their command, which quietly pulls down tools like Amatera stealer, ZigCryptoStealer, and NetSupport Manager. Here’s the nasty part: once that runs, it can steal your credentials and crypto, use a vulnerable driver to kill EDR, and give remote access to your machine. They even hide behind legit platforms like the BNB Smart Chain so web filters don’t block it. Aha rule: real CAPTCHAs never ask you to copy and paste commands. If any website does that, stop, close the tab, and report it to IT or security right away.