PhantomCaptcha RAT Attack Targets Aid Groups Supporting Ukraine
News Source : HackRead
News Summary
- Attack targeted Red Cross, UNICEF, Norwegian Refugee Council, and Ukrainian government administrations in regions like Donetsk and Dnipropetrovsk.
- Attack began with official-looking emails from the Ukrainian President’s Office, which included a malicious PDF.
- Clicking a link in the PDF directed victims to zoomconference.app, a domain appearing as a legitimate Zoom site.
- This domain, hosted on a Russian-provider-owned server in Finland, presented a fake Cloudflare captcha page.
- This was a trap to trick people into downloading a secret spying tool.
A recent, highly coordinated cyberattack, codenamed PhantomCaptcha, targeted several major humanitarian and government groups supporting war relief efforts in Ukraine, according to new research fro [+3229 chars]
Never miss a story from us, subscribe to our newsletter