
The Government Cyber Defense Unit, part of Israel's National Digital Directorate, issued a warning Thursday evening about an increase in the international ShadowCaptcha attack campaign, which uses social engineering techniques to trick users into executing malicious code themselves.
According to the warning, attackers display a fake "I'm not a robot" verification screen-sometimes even on legitimate websites that have been compromised-and instruct users to copy and paste a command into a window on their computer.
Following these instructions may result in the download of malware that enables attackers to take control of the computer, steal information, mine cryptocurrency, and even deploy ransomware.
The National Digital Agency noted that the latest wave of attacks also uses public blockchain networks to deliver malicious code, making it more difficult for security systems to detect and remove the threat.
The Directorate emphasized that a legitimate CAPTCHA verification is performed exclusively within a web browser by checking a box or selecting images, and never requires users to open a command window, press keyboard shortcuts, or paste text.
National Digital Directorate Director General Brig. Gen. (res.) Nati Cohen said, "The ShadowCaptcha campaign demonstrates how attackers continue to refine their methods. They have turned the familiar 'I'm not a robot' screen into a trap, and are now also using blockchain infrastructure to distribute malicious code and make it harder to detect."
"It is important for the public to remember one simple rule: a genuine CAPTCHA test will never ask you to open a command window on your computer or paste a command," he concluded.
