Spreely +

  • Home
  • News
  • TV
  • Podcasts
  • Movies
  • Music
  • Social
  • Shop
  • Advertise

Spreely News

  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
Home»Spreely News

Thousands of Compromised Sites Push Fake CAPTCHA Malware Trap

Kevin ParkerBy Kevin ParkerSeptember 14, 2026 Spreely News No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers are flagging a nasty malware campaign that turns legitimate websites into bait. A fake CAPTCHA can appear on a real business page, then pressure Windows users into running commands that quietly install malware. The trap looks ordinary at first, which is exactly why it is working.

More than 5,400 compromised sites have reportedly been pulled into the scheme, spread across thousands of organizations and a wide mix of small businesses. Clinics, plumbing companies, online stores and other familiar local names have all shown up in the mix. That means the danger is not limited to sketchy corners of the web, because a trusted site can suddenly become the front door for an attack.

The method is straightforward but slick. A visitor lands on a compromised page, sees what looks like a routine verification challenge, and then gets told to open Windows Run and paste a command. That is the moment the game changes, because the command can pull down malware and launch it on the spot.

What makes the scam especially effective is its use of routine behavior against the user. People are used to CAPTCHAs asking for a checkbox, a picture selection, or a quick proof that they are human. When the prompt feels familiar, the brain tends to relax, and that is when the attacker slips in a dangerous step disguised as part of the process.

Researchers say the campaign has been observed on sites running common platforms, especially WordPress and sometimes PrestaShop. Even more unsettling, investigators still do not know how the attackers initially got inside those sites. The scale suggests this is not a random one-off, but a broad campaign that keeps spreading through ordinary business websites.

The attack also leans on a more unusual trick behind the scenes. Instead of storing all its instructions on a basic web server, the scheme uses the BNB Smart Chain test network and smart contracts to feed compromised sites their next move. That gives the criminals a flexible system that is cheaper to run and harder to knock offline with standard takedown methods.

There is another layer of trouble, too. Some versions of the attack are now skipping the fake CAPTCHA entirely and using WebRTC, a browser technology usually tied to video calls and live communication. In that setup, the browser can receive malicious code through an encrypted connection, which makes the payload easier to hide and harder to spot.

See also  AI Is Transforming Cancer Treatment, From Melanoma To Fertility Care

That kind of shift is a reminder that the tactics keep changing even when the goal stays the same. The criminals want the victim to trust the page long enough to take one unsafe step, and then the damage starts fast. The technical details matter to researchers, but the warning for everyday users is simpler than that.

The biggest red flag is also the easiest to remember: a real website should never tell someone to open Windows Run, PowerShell, or Command Prompt just to prove they are human. A CAPTCHA may be annoying, but it should stay inside the browser and never ask for system commands. The second a page pushes instructions outside the browser, it should be treated like a threat.

That advice matters even more for small businesses running their own websites. Security teams are urging site owners to check content management files, look for suspicious JavaScript changes, and remove plugins that are no longer needed. Keeping WordPress, PrestaShop and related tools updated is basic hygiene, but it can make a real difference when attackers are hunting for weak spots.

If a suspicious CAPTCHA appears, the safest move is to close the page and move on. If a command was already pasted, disconnect the device from the internet, scan it with reputable antivirus software, and change important passwords from a different trusted device. A familiar business site can feel harmless in the moment, but this scam is built to turn that comfort into a mistake.

Technology
Avatar photo
Kevin Parker

Keep Reading

Forgotten 1980s Pontiac Trans Am Outsprinted Most American Cars

Ridgid 18V Tools Earn Hundreds Of 5-Star Ratings Online

OpenAI Delays IPO, Altman Cites AI Safety Concerns

NYC Orders Emergency Cleaning After Bronx Legionnaires Surge

Bedroom Light Exposure Linked To Higher Heart Disease Risk

NFL Best And Worst: From The Vikings' Pressure Cooker To The Rams’ Head-Scratcher

Add A Comment
Leave A Reply Cancel Reply

All Rights Reserved

Policies

  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports
  • Politics
  • Business
  • Finance
  • Technology
  • Health
  • Sports

Subscribe to our newsletter

Facebook X (Twitter) Instagram Pinterest
© 2026 Spreely Media. Turbocharged by AdRevv By Spreely.

Type above and press Enter to search. Press Esc to cancel.