Warbixin Degdeg ah

Israel National Digital Agency Uncovers Global Cyberattack Campaign “ShadowCaptcha”

Israel National Digital Agency uncovers ongoing global cyberattack campaign "ShadowCaptcha" using fake CAPTCHA pages to execute malicious commands on

Israel National Digital Agency War Degdeg ah

 

In August 2025, Israel National Digital Agency researchers uncovered an ongoing large-scale cybercrime campaign leveraging a ClickFix technique. The campaign uses a fake Cloudflare or Google CAPTCHA page to trick victims into executing malicious commands via compromised WordPress websites.

Retrospective analysis indicates the campaign has been active for at least the past year with the potential to impact thousands of organizations worldwide. Analysis uncovered over 100 compromised WordPress sites injected with malicious JavaScript redirecting to attacker-controlled infrastructure, and hundreds of malware samples spanning multiple families and variants.

The campaign, which we have dubbed ShadowCaptcha, blends social engineering, living-off-the-land binaries (LOLBins), and multi-stage payload delivery to gain and maintain a foothold in targeted systems. The ultimate objectives of ShadowCaptcha are collecting sensitive information through credential harvesting and browser data exfiltration, deploying cryptocurrency miners to generate illicit profits, and even causing ransomware outbreaks. This combination of tactics underscores its nature as an opportunistic financially motivated operation, blending social engineering, stealthy persistence, and monetization through both data theft and cryptomining.

If undetected, ShadowCaptcha can result in prolonged unauthorized access to internal systems, sustained cryptomining that degrades performance and increases operational costs, and large-scale exfiltration of sensitive data that could lead to reputational damage, regulatory penalties, and financial losses. The opportunistic nature of this campaign means that any internet-facing organization is a potential target, regardless of size or sector.

Given its scale and adaptability, we recommend creating detection and prevention rules targeting the TTPs detailed in this report, alongside awareness training for end-users to recognize and avoid the broader ClickFix social engineering technique, to reduce risk and prevent future incidents

 

author avatar
Israel National Digital Agency
Cusbooneysiin Jebinta Toos ah

War Degdeg ah Dabagal

Wararka jebinta waqtiga dhabta ah ee ka imaanaya Israel iyo Bariga Dhexe. La soco horumarka ugu dambeeya sida ay u dhacaan.

Sabti, 18 Abriil 2026 Si joogto ah ayaa loo cusbooneysiinayaa
Siyaasad 2 saacadood ka hor Cusub

Maanta oo kale, waxaan la hadli doonaa dad aad u tiro badan oo ka qayb galaya shirka Turning Point USA ee ka dhacaya Gobolka Arizona ee weyn, ka dibna waxaan ku noqon doonaa Aqalka Cad, sidaas darteed,

Trump oo ka maqnaan doona xaflad dhalasho oo uu lahaan lahaa Ronny Jackson oo ka dhici doonta Mar-a-Lago, sababo la xiriira khudbad uu ka jeedin doono Arizona iyo dib ugu laabasho Aqalka Cad.

Ganacsi 2 saacadood ka hor Cusub

Saamaynta Trump: Apple Waxay Ballaaraysaa Barnaamijkeeda Wax-soo-saarka Maraykanka Iyada Oo La Shaqaynaysa 4 Wakaaladood:

Apple waxa ay ballaarisaa barnaamijkeeda wax-soo-saarka ee Maraykanka, waxana ay ku dartay afar cusub oo la-hawlgalayaal ah, tallaabo ay qaar ka mid ahi ku xidheen baaqyadii hore ee Donald Trump ee wax-soo-saarka gudaha ah.

Siyaasad 2 saacadood ka hor Cusub

Senetka oo ansixisay ku-xigeenka cusub ee “Dagaalka Musuqmaasuqa” ee Waaxda Caddaaladda, Colin McDonald — iyadoo uu taageerayo Madaxweyne Ku-xigeenka Vance:

Donald Trump waxa uu qoraal soo dhigay bartiisa Truth Social oo ku saabsan aqbalida Senet-ka ee Colin McDonald oo noqday ku-xigeenka cusub ee "Dagaalka Musuqmaasuqa" ee Waaxda Cadaaladda.

Siyaasad 8 saacadood ka hor Cusub

Mar kale!

Donald Trump oo ka hadlayay barxadiisa Truth Social ayaa sheegay in heshiiska aanu ku xirnayn Lubnaan, balse uu ballan qaaday inuu "KA DHIGI DOONO LUBNAAN MARLABAAD MID WEYN!".