Cybersecurity News

Filters
Tag
Reset

Filtered by tag: cryptomining × Clear

Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto

Matched: cryptocurrency

A ClickFix campaign is targeting Mac users with a fake CAPTCHA page styled as "TrustKey" that tricks victims into running a malicious Terminal command. The command fetches an AppleScript payload via Cloudflare Workers, installs a persistent LaunchAgent, and uses blockchain-based EtherHiding to locate its command server. The backdoor steals browser credentials, keychain data, and crypto wallet information, while also deploying XMRig to mine Monero. Any CAPTCHA requesting Terminal access should be treated as malicious.

Threat Actors Achieve Persistence After SQL Injection

Attackers exploited SQL injection vulnerabilities to compromise IIS servers, deploying the BadIIS malware to gain persistence. Once inside, they disabled Windows Defender to avoid detection, then silently installed a cryptominer to hijack system resources. The attack highlights how unpatched web application vulnerabilities can serve as entry points for multi-stage intrusions with lasting impact.