Tuesday, 02 January 2024 12:17 GMT

Hackers Exploit CAPTCHA, Webdav And Blockchain To Steal Credentials Arabian Post


(MENAFN- The Arabian Post) clearfix">Cybercriminals are combining fake Google CAPTCHA prompts, WebDAV-hosted DLLs, malicious Cloudflare Workers and BNB Smart Chain contracts in a multi-stage operation that deploys the Amatera information stealer and other payloads, according to new research from Cisco Talos.

The investigation began after Talos identified unusual endpoint activity at a Ukrainian government organisation in April 2026. A remote file disguised as“verification. google” was executed from a WebDAV path through the 32-bit version of Windows rundll32. exe, while the Windows WebClient service was started.

Talos said it assesses with moderate confidence that the activity was not aimed specifically at the Ukrainian organisation but formed part of a broader cryptocurrency and credential-theft campaign. Researchers track the activity linked to the“verification. google” branch as UAT-10820.

MENAFN10092026000152002308ID1111645440



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story