PhantomCaptcha RAT Uses Weaponized PDFs and “ClickFix” Cloudflare CAPTCHA Pages to Deliver Malware
## Cybersecurity: PhantomCaptcha Campaign Targets Ukrainian Relief Efforts
Cybersecurity: PhantomCaptcha Campaign Targets Ukrainian Relief Efforts
A sophisticated spearphishing campaign has been identified, targeting humanitarian organizations involved in Ukrainian war relief efforts. The campaign, known as PhantomCaptcha, utilizes weaponized PDFs and deceptive Cloudflare captcha pages to deploy a custom remote access trojan.
Initiated on Wed, Oct 8, 2025, the campaign specifically aimed at members of the International Committee of the Red Cross, UNICEF Ukraine office, Norwegian Refugee Council, and the Council of Europe's Register of Damage for Ukraine. Ukrainian governmental bodies in Donetsk, Dnipropetrovsk, Poltava, and Mikolaevsk regions were also targeted through emails masquerading as legitimate government documents.
SentinelLABS and the Digital Security Lab of Ukraine discovered this attack, which impersonated the Ukrainian President's Office to compromise key aid organizations.
Technical Details and Attack Methodology
A malicious eight-page PDF (SHA-256: e8d0943042e34a37ae8d79aeb4f9a2fa07b4a37955af2b0cc0e232b79c2e72f3) was distributed through emails pretending to be from Ukraine’s Presidential Office. The PDF included links directing victims to zoomconference[.]app , a domain simulating a Zoom site but hosted on Russian-owned infrastructure. The domain resolved to IP address 193.233.23[.]81 in Finland and was operational for a single day before being taken offline.
The campaign employed a social engineering technique similar to "ClickFix" or "Paste and Run." Victims were directed to a fake Zoom site where a counterfeit Cloudflare DDoS protection gateway attempted to establish WebSocket connections to the attackers’ server.
A sophisticated spearphishing campaign has been identified, targeting humanitarian organizations involved in Ukrainian war relief efforts.
Upon interacting with the fake captcha, victims were instructed to execute a command that bypassed traditional security controls, using a heavily obfuscated PowerShell script to download a second-stage payload. This script collected system information and transmitted it to a command-and-control server.
The final stage involved deploying a PowerShell backdoor establishing persistent WebSocket connections to wss://bsnowcommunications[.]com:80 , enabling remote command execution and data exfiltration.
Extended Infrastructure and Mobile Threats
The attackers' infrastructure setup began in March 2025. The domain goodhillsenterprise[.]com was registered on Mar 27, 2025, with content themed around an entertainment venue in Lviv, Ukraine. SSL certificates were issued in September, and timestamps from the PDF were updated immediately before the October attack.
An additional mobile attack vector was discovered, featuring fake Android applications themed around Ukrainian businesses. The malicious APK gathered extensive device data and transmitted it to hardcoded command-and-control servers.
SentinelLABS identified potential overlaps with the COLDRIVER threat cluster based on observed tactics, techniques, and procedures. The command-and-control infrastructure remained active even after user-facing domains were disabled, indicating a strategy to maintain access to compromised systems while protecting core infrastructure.
Based on reporting by GBHackers.
