The phony CAPTCHA's "verification" steps include: 1. Press Windows button + R key 2. Press Ctrl-V 3. Press enter.
https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/160/976/012/619/024/original/7660ca7800fa00a1.png
Called it. Wrote this back in Sept. 2024, about a clever Windows Powershell phishing scam that was targeting developers at the time. It uses a fake CAPTCHA that asks visitors to distinguish themselves from bots by pressing a combination of keyboard keys that causes Microsoft Windows to download password-stealing malware. Everyone said, bah, devs will never fall for this. Maybe, I said, but your average user would for sure.
Judging from the number of recent media reports, it appears this one is pretty widespread at the moment.
https://krebsonsecurity.com/2024/09/this-windows-powershell-phish-has-scary-potential/
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.