Tuesday, April 1, 2025
HomeComputer SecurityHackers Hiding Malware behind Captcha to Bypass Secure Email Gateways

Hackers Hiding Malware behind Captcha to Bypass Secure Email Gateways

Published on

SIEM as a Service

Follow Us on Google News

Hackers using Captcha to hide the presence of malware and to evade email security gateways. By using this technique attackers show that email is sent human and evades detection.

Attackers use various social engineering methods to trick the users to believe the emails is from a legitimate source, here the email’s are from a compromised account at @avis.ne.jp.

Hidden Malicious Page Behind Captcha

Cofense identified a new email campaign that alerts recipients that they received a new voicemail message. The voice was with a preview that tempts users to listen to the full message.

Email Body credits: Cofense

The email contains a play button which has an embedded hyperlink pointing to the page that contains captcha, this step is to bypass the automated analysis tools and to bypass secure email gateways.

Once the user click’s on the link they get directed to the captcha page, once the captcha check completed users taken to the main phishing page that hosted on MSFT infrastructure.

The phishing page asks the user to select a Microsoft account to log in when the victim login all their credentials are captured.

Phishing page Image credits: Cofense

“Both pages are legitimate Microsoft top-level domains, so when checking these against domain reputation databases we receive a false negative and the pages come back as safe,” reads Cofense report.

The attack method is nothing new, the important part is the Captcha page which makes the attack more successful by evading the security controls placed.

Email Header Analysis always helps you in preventing such malicious threat, emails are the critical business asset and they need to be secured.

Before clicking on a link, investigate that the website is safe, there are various methods to the check is this website safe or not.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Massive 400GB X (Twitter) Data Leaked – 2.8 Billion Records Exposed

A colossal 400GB trove containing data from 2.873 billion X (formerly Twitter) users has...

PortSwigger Launches Burp AI to Enhance Penetration Testing with AI

PortSwigger, the makers of Burp Suite, has taken a giant leap forward in the...

Chord Specialty Dental Partners Data Breach Exposes Customer Personal Data

Chord Specialty Dental Partners is under scrutiny after revealing a data breach that compromised...

Kentico Xperience CMS XSS Vulnerability Allows Remote Code Execution

Kentico Xperience CMS, a widely used platform designed for enterprises and organizations, is under...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Operation HollowQuill – Weaponized PDFs Deliver a Cobalt Strike Malware Into Gov & Military Networks

In a recent revelation by SEQRITE Labs, a highly sophisticated cyber-espionage campaign, dubbed Operation...

Earth Alux Hackers Use VARGIET Malware to Target Organizations

A new wave of cyberattacks orchestrated by the advanced persistent threat (APT) group Earth...

DarkCloud: An Advanced Stealer Malware Sold on Telegram to Target Windows Data

DarkCloud, a highly advanced stealer malware, has emerged as a significant threat to Windows...