Fake CAPTCHA on Crooked Timber tried to trick user into running malicious script
A user visiting the news blog Crooked Timber this morning encountered a fraudulent CAPTCHA page designed to look like a legitimate Google verification prompt. Instead of a standard check, the page instructed the user to open the Windows Run dialog and paste a command from their clipboard. The clipboard had been silently loaded with a PowerShell command that would have downloaded and executed a malicious script from an external URL. The user recognized the suspicious instructions before acting and confirmed the threat by consulting an AI tool at work. The incident highlights a growing social engineering technique that disguises malware delivery as routine browser verification steps.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in