
Fake CAPTCHA Tricks Ukrainians Into Running Malware
CERT-UA reports a Sandworm-linked group (UAC-0145) is using fake CAPTCHA checks on compromised websites to persuade Ukrainian visitors to run PowerShell…
Ukraine’s CERT-UA says Russian-linked attackers are using fake CAPTCHA prompts on hacked websites to trick people into running malicious PowerShell commands themselves. The page pretends it’s verifying the visitor is human, but instead guides them to open the Windows Run box and execute attacker-provided code, leading to reconnaissance and potential further compromise.
According to CERT-UA, a campaign linked to UAC-0145, described as a branch of Sandworm, uses compromised websites to display a fake CAPTCHA verification screen. Instead of the usual image selection or checkbox, the page instructs visitors to open the Windows Run dialog, paste a PowerShell command that has already been placed on their clipboard, and press Enter. That single action executes attacker-controlled code on the victim's own machine.
Once the command runs, the campaign moves into reconnaissance. Payload activity includes downloading and running a tool referred to as ScoutCurl, which profiles the machine and helps attackers decide on further steps. At least ten compromised websites have been tied to this activity since early June, with reported growth through spring and summer.
This technique avoids some of the friction that comes with getting a user to click a malicious link or open an attachment. Instead, it walks the victim through a short, guided sequence framed as a routine security check. The instructions are presented as helpful technical advice to resolve a supposed access issue, which lowers suspicion because the user believes they are following normal troubleshooting steps rather than installing malware themselves.
CAPTCHA prompts are also a familiar, low-friction part of everyday browsing, so most people do not expect one to ask for anything beyond clicking images or ticking a box. That familiarity works against the user here, since the unusual step (opening Run and pasting a command) is dressed up as just another verification requirement.
Organizations can reduce risk from this technique with a few practical habits:
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Visitors to a compromised website are shown a fake CAPTCHA that instructs them to open the Windows Run dialog, paste a PowerShell command from their clipboard, and press Enter, which executes attacker-provided code instead of verifying they are human.
CERT-UA attributes the activity to UAC-0145, described as a branch of Sandworm.
The payload activity includes downloading and running reconnaissance tooling called ScoutCurl to profile the machine and decide what to do next.
A genuine CAPTCHA will never ask you to press Windows+R, open the Run dialog, paste a command, or press Enter to verify you are human.
You open a normal website… and the CAPTCHA tells you to press Windows plus R and run a command to prove you’re human. This is a real campaign CERT-UA links to UAC-0145, a Sandworm branch. Their fake CAPTCHA walks you through opening the Windows Run box and pasting a PowerShell command, so you basically hack yourself. The moment you hit Enter, their tooling, like ScoutCurl, can profile your machine and decide the next move. Remember this: a genuine CAPTCHA will never tell you to press Windows plus R, open Run, paste a command, or hit Enter to verify you’re human. If any CAPTCHA or website ever asks you to run a command, stop immediately and report the page to our security team, don’t follow the steps.

CERT-UA reports a Sandworm-linked group (UAC-0145) is using fake CAPTCHA checks on compromised websites to persuade Ukrainian visitors to run PowerShell…

Ukraine’s CERT says the Russia-linked Sandworm group is tricking targets into infecting their own PCs using compromised websites that display fake CAPTCHA…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

A malvertising campaign is luring users with fake free “AI tool” downloads (recipe/meal-planning apps) delivered via paid search ads. Even when Microsoft…

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software…