Hackers Exploit CAPTCHA, Webdav And Blockchain To Steal Credentials Arabian Post
The investigation began after Talos identified unusual endpoint activity at a Ukrainian government organisation in April 2026. A remote file disguised as“verification. google” was executed from a WebDAV path through the 32-bit version of Windows rundll32. exe, while the Windows WebClient service was started.
Talos said it assesses with moderate confidence that the activity was not aimed specifically at the Ukrainian organisation but formed part of a broader cryptocurrency and credential-theft campaign. Researchers track the activity linked to the“verification. google” branch as UAT-10820.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment