New PhantomCaptcha RAT Weaponized PDFs to Deliver Malware Using ‘ClickFix’-Style Cloudflare Captcha Pages
A targeted spearphishing campaign has been identified, affecting humanitarian organizations and Ukrainian government agencies. This operation uses malicious PDF attachments and fraudulent Cloudflare verification pages to deploy a WebSocket-based remote…
A targeted spearphishing campaign has been identified, affecting humanitarian organizations and Ukrainian government agencies. This operation uses malicious PDF attachments and fraudulent Cloudflare verification pages to deploy a WebSocket-based remote access trojan.
Initially detected in early October 2025, the operation displays significant planning and compartmentalization. The threat actors conducted the campaign over six months before execution.
The campaign specifically targeted members of the International Red Cross, Norwegian Refugee Council, UNICEF, and regional government administrations in Ukraine, using emails that impersonated the Ukrainian President's Office.
Opening the malicious PDF led recipients to a fake Cloudflare DDoS protection gateway, mimicking legitimate security verification pages.
The attackers registered the domain zoomconference.app to simulate a legitimate Zoom conference service, deploying the malicious infrastructure on Russian-owned VPS servers in Finland.
SentinelLABS researchers identified that the attackers maintained their infrastructure for only 24 hours before shutting down public-facing domains, while keeping backend command-and-control servers operational, indicating professional-grade operational security.
A targeted spearphishing campaign has been identified, affecting humanitarian organizations and Ukrainian government agencies.
The operation began in March 2025, with SSL certificates issued in September, pointing to careful preparation before the October strike.
The ClickFix Infection Mechanism and Multi-Stage Payload Delivery
The PhantomCaptcha campaign utilizes the ClickFix social engineering technique, adopted by threat actors since mid-2024.
Victims encountering the fake Cloudflare page see a simulated reCAPTCHA interface with an "I'm not a robot" checkbox. Clicking this checkbox initiates a popup in Ukrainian, instructing users to copy a token and paste it into the Windows Run dialog using Windows+R.
This action executes malicious PowerShell code, starting the infection chain.
The attack relies on a JavaScript function named copyToken() that downloads and executes a PowerShell script. The attackers distributed three payload stages, starting with a heavily obfuscated PowerShell downloader.
The second stage conducted system reconnaissance , gathering system data and encrypting it for transmission.
The final payload was a WebSocket-based remote access trojan capable of executing arbitrary commands and data exfiltration. It disabled PowerShell command history logging to prevent forensic analysis , ensuring persistent access.
Based on reporting by Cyber Security News.
