{"id":72152,"date":"2025-10-31T13:45:10","date_gmt":"2025-10-31T05:45:10","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=72152"},"modified":"2025-10-29T13:46:48","modified_gmt":"2025-10-29T05:46:48","slug":"i-am-not-a-robot-captchas-used-to-spread-malware-hp-warns","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2025\/10\/31\/i-am-not-a-robot-captchas-used-to-spread-malware-hp-warns\/","title":{"rendered":"&#8216;I Am Not a Robot&#8217; CAPTCHAs used to spread malware, HP warns"},"content":{"rendered":"<p><strong>HP Inc. issued the latest <a tabindex=\"0\" href=\"https:\/\/threatresearch.ext.hp.com\/hp-wolf-security-threat-insights-report-march-2025\/\">HP Threat Insights Report<\/a>, highlighting rising usage of fake CAPTCHA verification tests which allow threat actors to trick users into infecting themselves. The campaigns show attackers are capitalizing on people\u2019s increasing familiarity with completing multiple authentication steps online \u2013 a trend HP calls \u2018click tolerance\u2019.\u00a0<\/strong><\/p>\n<p>With analysis of real-world cyberattacks, the HP Threat Insights Report helps organizations to keep up with the latest techniques cybercriminals are using to evade detection and breach PCs.\u202fBased on data from millions of endpoints running HP Wolf Security, notable campaigns identified by HP threat researchers include:<\/p>\n<ul>\n<li><b>CAPTCHA Me If You Can:<\/b>\u00a0As bots get better at bypassing CAPTCHAs, authentication has grown more elaborate \u2013 meaning users have become more accustomed to jumping through hoops to prove they are human. HP threat researchers identified multiple campaigns where attackers crafted malicious CAPTCHAs. Users were\u00a0directed to attacker-controlled sites, and prompted to complete a range of fake authentication challenges. Victims were tricked into running a malicious PowerShell command on their PC that ultimately installed the Lumma Stealer remote access trojan (RAT).<\/li>\n<li><b>Attackers Capable of Accessing End-Users\u2019 Webcams and Microphones to Spy on Victims:\u00a0<\/b>A second campaign saw attackers<b>\u00a0<\/b>spreading an open source RAT, XenoRAT, with advanced surveillance features such as microphone and webcam capture. Using social engineering techniques to convince users to enable macros in Word and Excel documents, attackers could control devices, exfiltrate data, and log keystrokes \u2013 showing Word and Excel still present a risk for malware deployment.<\/li>\n<li><b>Python Scripts Used for SVG Smuggling<\/b>: Another notable campaign shows how attackers are delivering malicious JavaScript code inside Scalable Vector Graphic (SVG) images to evade detection. These images are opened by default in web browsers and execute the embedded code to deploy seven payloads\u2014including RATs and infostealers\u2014offering redundancy and monetization opportunities for the attacker. As part of the infection chain, the attackers also used obfuscated Python scripts to install the malware. Python\u2019s popularity \u2013 which is being further boosted by rising interest in AI and data science \u2013 means it is an increasingly attractive language for attackers to write malware, as its interpreter is widely installed.<\/li>\n<\/ul>\n<p>Patrick Schl\u00e4pfer, Principal Threat Researcher in the HP Security Lab, comments:\u202f &#8220;A common thread across these campaigns is the use of obfuscation and anti-analysis techniques to slow down investigations. Even simple but effective defence evasion techniques can delay the detection and response of security operations teams, making it harder to contain an intrusion. By using methods like direct system calls, attackers make it tougher for security tools to catch malicious activity, giving them more time to operate undetected \u2013 and compromise victims endpoints.&#8221;<\/p>\n<p>By isolating threats that have evaded detection tools on PCs \u2013 but still allowing malware to detonate safely inside secure containers \u2013 HP Wolf Security has specific insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on more than 65 billion email attachments, web pages, and downloaded files with no reported breaches.<\/p>\n<p>The report, which examines data from calendar Q4 2024, details how cybercriminals continue to diversify attack methods to bypass security tools that rely on detection, such as:<\/p>\n<ul>\n<li>At least 11% of email threats identified by\u202f<a tabindex=\"0\" href=\"https:\/\/www.hp.com\/gb-en\/security\/enterprise-pc-security.html\">HP Sure Click<\/a>\u202fbypassed one or more email gateway scanners.<\/li>\n<li>Executables were the most popular malware delivery type (43%), followed by archive files (32%).<\/li>\n<\/ul>\n<p>Dr. Ian Pratt, Global Head of Security for Personal Systems at HP Inc., comments:\u202f\u202f\u201cMulti-step authentication is now the norm, which is increasing our \u2018click tolerance.\u2019 The research shows users will take multiple steps along an infection chain, really underscoring the shortcomings of cyber awareness training. Organizations are in an arms race with attackers\u2014one that AI will only accelerate. To combat increasingly unpredictable threats, organizations should focus on shrinking their attack surface by isolating risky actions \u2013 such as clicking on things that could harm them. That way, they don\u2019t need to predict the next attack; they\u2019re already protected.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As bots get better at bypassing CAPTCHAs, authentication has grown more elaborate \u2013 meaning users have become more accustomed to jumping through hoops to prove they are human.<\/p>\n","protected":false},"author":6,"featured_media":72153,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[1481,51,54],"class_list":["post-72152","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-white-papers","tag-cybersecurity","tag-hp","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=72152"}],"version-history":[{"count":1,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72152\/revisions"}],"predecessor-version":[{"id":72154,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/72152\/revisions\/72154"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/72153"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=72152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=72152"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=72152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}