Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New PhantomCaptcha RAT Weaponized PDFs to Deliver Malware Using ‘ClickFix’-Style Cloudflare Captcha Pages

A targeted spearphishing campaign has been identified, affecting humanitarian organizations and Ukrainian government agencies. This operation uses malicious PDF attachments and fraudulent Cloudflare verification pages to deploy a WebSocket-based remote…

A targeted spearphishing campaign has been identified, affecting humanitarian organizations and Ukrainian government agencies. This operation uses malicious PDF attachments and fraudulent Cloudflare verification pages to deploy a WebSocket-based remote access trojan.

Initially detected in early October 2025, the operation displays significant planning and compartmentalization. The threat actors conducted the campaign over six months before execution.

The campaign specifically targeted members of the International Red Cross, Norwegian Refugee Council, UNICEF, and regional government administrations in Ukraine, using emails that impersonated the Ukrainian President's Office.

Opening the malicious PDF led recipients to a fake Cloudflare DDoS protection gateway, mimicking legitimate security verification pages.

The attackers registered the domain zoomconference.app to simulate a legitimate Zoom conference service, deploying the malicious infrastructure on Russian-owned VPS servers in Finland.

SentinelLABS researchers identified that the attackers maintained their infrastructure for only 24 hours before shutting down public-facing domains, while keeping backend command-and-control servers operational, indicating professional-grade operational security.

A targeted spearphishing campaign has been identified, affecting humanitarian organizations and Ukrainian government agencies.
Rachel Green · Thehackingpost

The operation began in March 2025, with SSL certificates issued in September, pointing to careful preparation before the October strike.

The ClickFix Infection Mechanism and Multi-Stage Payload Delivery

The PhantomCaptcha campaign utilizes the ClickFix social engineering technique, adopted by threat actors since mid-2024.

Victims encountering the fake Cloudflare page see a simulated reCAPTCHA interface with an "I'm not a robot" checkbox. Clicking this checkbox initiates a popup in Ukrainian, instructing users to copy a token and paste it into the Windows Run dialog using Windows+R.

This action executes malicious PowerShell code, starting the infection chain.

Advertisement

The attack relies on a JavaScript function named copyToken() that downloads and executes a PowerShell script. The attackers distributed three payload stages, starting with a heavily obfuscated PowerShell downloader.

The second stage conducted system reconnaissance , gathering system data and encrypting it for transmission.

The final payload was a WebSocket-based remote access trojan capable of executing arbitrary commands and data exfiltration. It disabled PowerShell command history logging to prevent forensic analysis , ensuring persistent access.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories