Cyber Security News

Hackers Use Fake CAPTCHA to Install Malware That Kills 145 Security Processes

Hackers are using fake CAPTCHA pages to push a malware loader that can shut down security software before a follow-on payload runs.

The campaign combines compromised WordPress websites, a familiar browser verification prompt, and a Windows command that victims are persuaded to execute themselves.

The operation uses ErrTraffic, a malware delivery service that creates ClickFix lures styled as Google reCAPTCHA, Cloudflare Turnstile, or a Windows error screen.

A visitor who follows the on-screen steps unknowingly runs a copied PowerShell command, opening the door to the Cruciferra loader and the Remus information stealer.

Analysts at eSentire said in a report shared with Cyber Security News (CSN) that they identified several ErrTraffic-generated campaigns in late July 2026.

The finding shows how attackers combine polished social engineering with a kernel-level method for disabling endpoint protections.

Sales thread on underground hacking forum (Source – Esentire)

The impact is serious because Cruciferra is designed to blind a device before more harmful activity begins. It abuses a signed but vulnerable driver to terminate selected antivirus and endpoint detection processes, reducing the chance that the next stage will be stopped or reported.

Hackers Use Fake CAPTCHA

The attack begins on a legitimate WordPress site that attackers have already compromised. An obfuscated JavaScript injection contacts attacker-controlled infrastructure, retrieves the lure, and presents a verification page that looks routine.

Rather than exploiting a browser flaw, the page relies on a person completing the attacker’s instructions. It copies a malicious PowerShell command to the clipboard and asks the visitor to open PowerShell with Windows Key plus X, paste the command, and run it.

Subsequent PowerShell stages use a legitimate Microsoft-signed program to side-load Cruciferra as mscoree.dll.

The loader then uses process hollowing to place the Remus stealer inside ServiceModelReg.exe. Similar malicious WordPress script injections show why website owners must watch for unauthorized changes.

ClickFix lure (Source – Esentire)

ErrTraffic also uses Polygon blockchain smart contracts to locate its current command server. That design lets operators rotate infrastructure without rewriting the code planted across compromised sites.

The service reportedly offers targeting filters and templates for Windows, Linux, and macOS, allowing affiliates to tailor a lure to the visitor and campaign.

The deception follows a broader pattern seen in fake CAPTCHA ClickFix campaigns, where attackers turn a familiar verification prompt into a malware delivery channel. Users should be cautious whenever a website asks them to paste text into a Windows tool to complete a CAPTCHA.

Driver Abuse Silences Defenses

Cruciferra’s most concerning feature is its ability to load DCRCVDrv.sys, a signed driver with a weakness that lets software request process termination from the Windows kernel.

When the loader is configured with its privilege-bypass and security-killing options, it writes the driver to the Windows Temp directory, creates a service, and begins targeting defenses.

Researchers found 145 antivirus and EDR-related process names configured by default. The list includes products from Microsoft, CrowdStrike, SentinelOne, Sophos, Kaspersky, McAfee, and others.

Killing these processes can remove valuable warning and containment controls before attackers steal data, spread through a network, or deploy additional malware.

Attack diagram (Source – Esentire)

This is a bring-your-own-vulnerable-driver technique, in which attackers use a real signed driver rather than an obviously malicious kernel component.

It reflects the same risk covered in reporting on driver attacks against EDR, where a vulnerable driver can give malware the leverage to neutralize security software.

Defenders should block the identified driver by hash in their security console and keep Microsoft’s vulnerable-driver protections enabled. Teams should also investigate unexpected driver services, browser pages that demand keyboard shortcuts, and PowerShell started immediately after clipboard activity.

User awareness training should make clear that real CAPTCHA checks do not ask people to paste commands into Windows. Organizations should treat a detection of the loader, driver, or listed network infrastructure as a possible active compromise.

Monitoring for malware disables endpoint defenses is important because loss of visibility may be the attacker’s first objective.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-25687e8d39db624f37d3e77aedf487a2dfd197f71a4730ea74f4e7a4341deaec2ffVulnerable DCRCVDrv.sys driver
SHA-147d922b0fd5d704025d14ef98ded46e74830a423Vulnerable DCRCVDrv.sys driver
MD5567c158ee0858f8e941d4ab7a6c18dbcVulnerable DCRCVDrv.sys driver
SHA-2560ae0a7f118b80e4655b8b86bb421c151a8f17930e76e714b2fa199409f3af9ceCruciferra DLL, mscoree.dll
Domainmakeverizyjar[.]infoErrTraffic command-and-control server
Domainanalysis-id-fmd[.]infoErrTraffic command-and-control server
Domainanalysis-id-lfg[.]infoErrTraffic command-and-control server
IPv4178.16.52[.]101ErrTraffic command-and-control server
Domainkarmactive[.]comCompromised WordPress site hosting an ErrTraffic injection
Domaintzpx[.]coursesRemus command-and-control server
Domainzelpx[.]gardenRemus command-and-control server

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption

Dark Caracal has returned with a new tool that helps attackers stay connected when defenders…

2 hours ago

Claude Code Opus 5 Auto Mode Hijacked via Prompt Injection to Execute Malicious Code

Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via…

3 hours ago

CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as…

3 hours ago

Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports

Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on…

5 hours ago

100+ Tech and Security Organizations Call for Global Cyber Defense Surge Against AI Attacks

More than 100 technology, cybersecurity, and financial-services organizations have joined OpenAI in an open letter…

6 hours ago

Hackers Abuse Active Directory SPN Misconfigurations for Stealthy Kerberoasting Attacks

Threat actors are increasingly abusing overlooked Active Directory service principal name (SPN) misconfigurations to launch…

7 hours ago