Loader
Advertisement

Russian hackers may have used fake CAPTCHA to hack Ukrainian government computers

Canva
Canva Copyright  Hackers are turning CAPTCHA checks into a trap
Copyright Hackers are turning CAPTCHA checks into a trap
By Roselyne Min
Published on
Share Comments Add Euronews on Google
Share Close Button

Researchers say the attack was likely part of a wider operation to steal cryptocurrency and login credentials by tricking users through a fake Google verification check to trick victims.

A suspicious cyberattack using fake CAPTCHA checks to target a Ukrainian government organisation has been linked to Moscow, according to a new report.

ADVERTISEMENT
ADVERTISEMENT

US tech giant Cisco said its cybersecurity researchers noticed unusual activity in the organisation's computer systems in April, asserting “with moderate confidence” that a Russian threat actor carried out the attack.

Cisco's researchers found malware known as Amatera running on the system, capable of stealing sensitive information.

It was also used to install software that could give an attacker access to the computer, including the ability to inspect files, transfer data and run commands, according to the company.

Cisco found that the software was configured to connect to a server with an IP address based in Russia.

The report could not verify whether any information was actually stolen from the Ukrainian organisation, whether hackers actively used that access or how the computer was initially infected.

Cisco researchers however assessed that it was part of a broader operation designed to steal cryptocurrency and credentials.

“It was not clear what started the execution chain,” the report said.

CAPTCHA checks as traps

In the Ukrainian system, Cisco researchers had seen a malicious file disguised with the name “verification.google” but could not trace what had caused it to run.

To understand how the Ukrainian infection might have been started, they searched for similar attacks and found another infection involving the same Amatera malware.

This time, they traced it back to compromised websites showing fake versions of Google’s CAPTCHA verification check, used to distinguish human visitors from automated bots.

But instead of simply asking users to tick a box or identify images, the fake check told them to open a window on their computer and paste in text that would run malware.

In that infection, Amatera was also used to install a program designed to steal cryptocurrency.

The program could monitor cryptocurrency wallet addresses victims copied and replace them with addresses controlled by the attackers, potentially redirecting payments.

Cisco says similarities between the infections suggest the attack against Ukraine may have started in the same way.

However, researchers could not confirm that the two infections began the same way or that the same group carried them out.

Go to accessibility shortcuts
Share Comments Add Euronews on Google

Read more