Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

PhantomCaptcha RAT Uses Weaponized PDFs and “ClickFix” Cloudflare CAPTCHA Pages to Deliver Malware

## Cybersecurity: PhantomCaptcha Campaign Targets Ukrainian Relief Efforts

Cybersecurity: PhantomCaptcha Campaign Targets Ukrainian Relief Efforts

A sophisticated spearphishing campaign has been identified, targeting humanitarian organizations involved in Ukrainian war relief efforts. The campaign, known as PhantomCaptcha, utilizes weaponized PDFs and deceptive Cloudflare captcha pages to deploy a custom remote access trojan.

Initiated on Wed, Oct 8, 2025, the campaign specifically aimed at members of the International Committee of the Red Cross, UNICEF Ukraine office, Norwegian Refugee Council, and the Council of Europe's Register of Damage for Ukraine. Ukrainian governmental bodies in Donetsk, Dnipropetrovsk, Poltava, and Mikolaevsk regions were also targeted through emails masquerading as legitimate government documents.

SentinelLABS and the Digital Security Lab of Ukraine discovered this attack, which impersonated the Ukrainian President's Office to compromise key aid organizations.

Technical Details and Attack Methodology

A malicious eight-page PDF (SHA-256: e8d0943042e34a37ae8d79aeb4f9a2fa07b4a37955af2b0cc0e232b79c2e72f3) was distributed through emails pretending to be from Ukraine’s Presidential Office. The PDF included links directing victims to zoomconference[.]app , a domain simulating a Zoom site but hosted on Russian-owned infrastructure. The domain resolved to IP address 193.233.23[.]81 in Finland and was operational for a single day before being taken offline.

The campaign employed a social engineering technique similar to "ClickFix" or "Paste and Run." Victims were directed to a fake Zoom site where a counterfeit Cloudflare DDoS protection gateway attempted to establish WebSocket connections to the attackers’ server.

A sophisticated spearphishing campaign has been identified, targeting humanitarian organizations involved in Ukrainian war relief efforts.
Amanda Parks · Thehackingpost

Upon interacting with the fake captcha, victims were instructed to execute a command that bypassed traditional security controls, using a heavily obfuscated PowerShell script to download a second-stage payload. This script collected system information and transmitted it to a command-and-control server.

The final stage involved deploying a PowerShell backdoor establishing persistent WebSocket connections to wss://bsnowcommunications[.]com:80 , enabling remote command execution and data exfiltration.

Extended Infrastructure and Mobile Threats

The attackers' infrastructure setup began in March 2025. The domain goodhillsenterprise[.]com was registered on Mar 27, 2025, with content themed around an entertainment venue in Lviv, Ukraine. SSL certificates were issued in September, and timestamps from the PDF were updated immediately before the October attack.

Advertisement

An additional mobile attack vector was discovered, featuring fake Android applications themed around Ukrainian businesses. The malicious APK gathered extensive device data and transmitted it to hardcoded command-and-control servers.

SentinelLABS identified potential overlaps with the COLDRIVER threat cluster based on observed tactics, techniques, and procedures. The command-and-control infrastructure remained active even after user-facing domains were disabled, indicating a strategy to maintain access to compromised systems while protecting core infrastructure.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories