Experts show how to distinguish between real and fake CAPTCHA online security tools

Cát Tiên (T/H) |

Experts warn that fake CAPTCHA scams are spreading, just one click can infect a device with data theft software.

Understanding CAPTCHA

Cybersecurity experts warn against a new trick being used by cybercriminals, which is fake CAPTCHA. This is a familiar Im Not a computer test designed to infect malware into users devices, according to indianexpress.

CAPTCHA is the acronym for the English phrase "Completely Automated Public Turing test to tell Computers and Humans Apart", translated as "ally automatically publicized Turing test to distinguish between computers and humans".

This tool often appears as an image select, enter distorted text, audio signal, or simply mark in the box (reCAPTCHA) to confirm you are human, not a bot.

However, according to Zakir Hussain Rangwala, CEO of BD Software Distribution Pvt Ltd (sponsoring cybersecurity solutions), cybercriminals have taken advantage of users' subjective habits to distribute malware through fake CAPTCHA.

These checks often appear on hacked websites, malicious advertisements, scam emails or fake domain names of reputable sites.

sophisticated attack methods

A report by CloudSEK's Threat Research and Information Analysis Agency (TRIAD) shows that an attack campaign is taking advantage of fake CAPTCHA to distribute Lumma Stealer software (specializing in stealing data on Windows).

The attackers created a fake website of Google CAPTCHA, stored on multiple servers and took advantage of the content distribution network (CDN) to increase legality.

When accessing, users will be instructed to open the Run dialogue (Win+R), paste a PowerShell command encoded with base64 and click Enter. This order downloaded Lumma Stealer from the investor's server to the victim's machine.

According to researcher Anshuman Das (CloudSEK), clicking on fake CAPTCHA is not immediately harmful, but following alongcoming instructions such as downloading a file or pasting a new command is a serious risk factor.

How to distinguish real and fake CAPTCHA

Expert Deependra Singh ( Betul Police, MP) pointed out:

CAPTCHA is actually on reputable websites, requiring simple operations such as selecting an image or typing.

Fake CAPTCHAs often require unusual actions such as allowing notification, downloading files, entering personal or financial information.

In addition, when users are required to check the URL to detect spelling errors, strange characters or suspicious domain names. CAPTCHA appearing as an independent pop-up instead of being integrated into the website is also a warning sign.

What to do immediately if you suspect you have encountered a fake CAPTCHA:

- Remove from the website immediately.

- Internet disconnection.

- Run a comprehensive viral scan.

- Delete cushioning memory, cookies, strange extension utilities.

- Change the passwords of important accounts.

- Dele all files that have just been downloaded but not yet opened.

Mr. Zakir Hussain Rangwala warned that sectors such as e-commerce and online games are likely to become targets of fake CAPTCHA because they involve a lot of sensitive data.

Users should not click on unknown origin links and always check the URL address. Because, a wrong pinch of the ball can cost both money and privacy.

Cát Tiên (T/H)
RELATED NEWS

TikTok upgrades online security and safety for young people

|

TikTok has just officially introduced a series of new safety and mental health features for adolescents and families when using the platform.

Security vulnerability allows hackers to take control of customers' vehicles

|

A security expert discovered a vulnerability in the dealer portal of a major automaker, which could expose personal data and vehicle information.

assault in apartment lobby: From small conflict to behavior gap

|

The incident of a man assaulting a woman right in the lobby of a Hanoi apartment building is ringing a warning bell about the behavioral culture in a collective living environment.

Construction of the second runway of Long Thanh airport day and night, completed on December 19

|

Dong Nai - The second runway of Long Thanh airport was requested by ACV to be completed by a consortium of contractors in accordance with the direction of the Prime Minister.

Miss Tieu Vy talks about real and fake social networks before attending the National KOL Conference

|

Miss Tran Tieu Vy will attend the National KOL Conference organized by Department A05- Ministry of Public Security in coordination with the National Cyber Security Association on August 18 in Hanoi.

Election and appointment of personnel in Hanoi, Ho Chi Minh City, Hai Phong, Ha Tinh

|

From August 11 to August 15, in the provinces/cities of Hanoi, Ho Chi Minh City, Hai Phong, Ha Tinh... decisions on election, appointment, transfer, and appointment of personnel will be implemented.

The qualities of People's Public Security people over 80 years of maturity

|

Minister Luong Tam Quang has just written an article about the quality of "Forgetting oneself for the country, serving the people" of the People's Public Security over 80 years of construction and growth.

Enterprises for workers - Workers for enterprises

|

On the evening of August 15, in Hanoi, Lao Dong Newspaper held a Ceremony to honor Outstanding Enterprises for Workers 2025 ( Program).

TikTok upgrades online security and safety for young people

NGUYỄN ĐĂNG |

TikTok has just officially introduced a series of new safety and mental health features for adolescents and families when using the platform.

Security vulnerability allows hackers to take control of customers' vehicles

HẠO THIÊN (T/H) |

A security expert discovered a vulnerability in the dealer portal of a major automaker, which could expose personal data and vehicle information.

iOS 16 sẽ giúp người dùng tự động điền mã CAPTCHA

Hoàng Tình |

Từ phiên bản iOS 16, Apple sẽ giúp người dùng tự động điền các mã CAPTCHA để phân biệt người thật hay máy móc khi truy cập vào trang web.