Fake CAPTCHA Campaign Delivers Malware That Kills Security Software
Hackers are using fake CAPTCHA pages to push a malware loader that can shut down security software before a follow-on payload runs.
The campaign combines compromised WordPress websites, a familiar browser verification prompt, and a Windows command that victims are persuaded to execute themselves.
A visitor who follows the on-screen steps unknowingly runs a copied PowerShell command, opening the door to the Cruciferra loader and the Remus information stealer.