Hackers exploit CAPTCHA, WebDAV and blockchain to steal credentials
Cybercriminals are combining fake Google CAPTCHA prompts, WebDAV-hosted DLLs, malicious Cloudflare Workers and BNB Smart Chain contracts in a multi-stage operation that deploys the Amatera information stealer and other payloads, according to new research from Cisco Talos. The investigation began after Talos identified unusual endpoint activity at a Ukrainian government organisation in April 2026.…
Cybercriminals are employing a multi-faceted strategy to pilfer login details and cryptocurrency assets, according to fresh research from Cisco Talos. The operation initiates with fraudulent Google CAPTCHA prompts, malicious WebDAV-hosted DLLs, malicious Cloudflare Workers and BNB Smart Chain contracts. In April 2026, Talos detected suspicious endpoint behavior at a Ukrainian governmental entity, leading to the identification of the "verification.google" branch of the campaign.
Through a WebDAV path, a disguised file named "verification.google" was executed, initiating the attack.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.