慣性聚合 高效追蹤和閱讀你感興趣的部落格、新聞、科技資訊
閱讀原文 在慣性聚合中打開

推薦訂閱源

博客园 - 司徒正美
V
V2EX
T
Tailwind CSS Blog
有赞技术团队
有赞技术团队
aimingoo的专栏
aimingoo的专栏
Apple Machine Learning Research
Apple Machine Learning Research
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
A
About on SuperTechFans
月光博客
月光博客
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI

The News International -latest news

Princess Beatrice, Eugenie preparing to forcefully resist Prince William's humiliating plans Reba McEntire gets candid about struggles behind her dream business Questions about Savannah Guthrie's father rise as Nancy search continues SpaceX: Falcon 9 boosts record-setting 'Cygnus XL' cargo spacecraft toward the ISS Nancy Guthrie kidnapping: Serial killer expert reveals possible 'retribution' motive Snoop Dogg hints at 'huge' television partnership with pal Simon Cowell Steven Spielberg breaks silence on losing huge sci-fi film to Christopher Nolan AI breakthrough slashes quantum computing errors—study finds Lena Dunham shares 'shocking' advice from her plastic surgeon: 'Let's call it what it is' Ralph Fiennes backs shocking female Voldemort in 'Harry Potter' reboot What is mental wellbeing, really? New study offers a clear answer Kate Middleton makes heartfelt plea to Prince Harry as new fear grows NASA Artemis II mission: real or fake conspiracys spread online 'Howl at the Moon': NASA's new strategy for cosmic curiosity North West goes all-in on goth glam for Coachella 2026 Sabrina Carpenter fans get 'now or never' warning ahead of 2026 Coachella Anyma issues apology after Coachella cancelled his set UK halts Chagos Islands handover plan after US opposition Halle Berry vows to return back to her past music era: 'I do miss our home studio' Microsoft clarifies Copilot is not just for entertainment use Meagan Good reveals beloved thing she sacrificed for husband Jonathan Majors Does being married lower cancer risk? Here's what research reveals White House shares Prince William, Kate Middleton's photo Inside deadly chimp 'civil war' in Uganda—What they reveal about human nature Nicola Peltz reacts after Brooklyn Beckham anniversary snub: 'Cosy' or lazy? Can AI be trusted? New documentary sparks fresh debate Princess Beatrice friend finally reacts to rumours her marriage to Edo heading for divorce John Legend opens up about his 'The Voice' prediction of winners Japan boosts semiconductor push to shield global supply chains: Here's why Noah Wyle addresses viral rumor after receiving top Hollywood honor Natasha Lyonne breaks silence over ICE detainment Grammy-nominated star Swae Lee prepares to headline Spring Fling concert OpenAI slams Elon Musk over ‘legal ambush’ ahead of $100B trial Prince Harry, Mark Dyer release statement after sued for libel by Sentebale Meghan Trainor details how online hate made her cry despite becoming a mom Man arrested for allegedly throwing Molotov cocktail at Sam Altman's house Stephen Curry's ankle injury sparks concerns ahead of LA Clippers game 27% of workers say AI replaces some job tasks: Survey Abbey Romeo, David Isaacman release joint statement after shocking split Brittney Griner signs with Sun in major deal as team builds for final seasons before Houston move Melania Trump's remarks reignite Epstein questions as survivors speak out Why Megan Fox is 'upset' with Machine Gun Kelly: Shocking details revealed Cyclone Vaianu: Strong winds and flood threat spark mass evacuations Jessica Biel urges parents to stop using viral parenting hack for major reason Brandon Valenzuela shines with first MLB home run as Blue Jays surge past Twins 10-4 Charlie Kirk's alleged assassin reveals shock 'opportunity' in ongoing case Tyler Rogers and Taylor Rogers show how twin brothers can dominate MLB in completely different ways OpenAI reports security issue in third-party tool Axios, assures user data protection Finneas O'Connell shares insight into wedding planning with fiancée Claudia Sulewski Raptors vs Knicks: OG Anunoby leaves game early with left ankle injury
偽裝驗證碼詐騙可在幾秒內安裝惡意軟體:這是如何保持安全的說明
2026-05-24 · via The News International -latest news
Fake CAPTCHA scam installs malware in seconds: Here’s how to stay safe
偽造 CAPTCHA 欺騙在幾秒內安裝惡意軟件:這是如何保持安全的

騙子們已經將互聯網最信任的安全功能之一武器化。一種日益增長的偽造 CAPTCHA 方案,被身份盜竊資源中心標記,透過將命令偽裝為正當的驗證提示,騙取用戶安裝 StealC 惡意軟件。

此攻擊繞過下載警告、彈窗阻擋器以及傳統的釣魚紅旗,只需要鍵盤輸入即可.

偽裝的 CAPTCHA 釣魚詐騙是如何運作的?

一個看似正常的網站顯示一個 CAPTCHA 方塊,用戶每天在銀行頁面和登錄屏幕上看到的類型。但不是點擊圖片或數字,訊息告訴他們要按下 Windows + R,然後 Ctrl + V,然後 Enter;這四個鍵盤輸入會導致駭擊。 

那個序列會打開隱藏的 Run 對話方塊,並啟動一個已等候在剪貼簿上的惡意腳本。基本上是使用者為它進行安裝,有點沒有意識到,而且沒有明顯的下載按鈕,也看不到明顯的彈出警告。

StealC 會在背景安靜地運行,悄悄收集有價值的資訊,而沒有明顯的跡象表示有問題。安全研究者指出它能竊取保存的密碼、瀏覽器登錄會話、自動填寫資訊,甚至加密貨幣錢包的細節。

很多受害者並沒有立刻察覺;他們只有在賬戶開始被攻擊者使用時才意識到,有時甚至在感染後幾週才發現,彷彿什麼都沒發生過一樣。

驗證碼提示讓人覺得安全,因為它們保護了合法服務。這次攻擊也傾向於消除通常的警告信號,例如沒有可疑下載、沒有奇怪的彈窗,以及沒有明顯的詐騙言論。相反,它提供直接、理性的指示,聽起來像是一些技術問題的正常排除故障。

一個真正的 CAPTCHA 不會要求你打開命令視窗、使用鍵盤快捷鍵,或貼上任何指令。如果你注意到這些指示,請立即關閉頁面。

如何避免偽 CAPTCHA 欺騙?

這是一份簡短的逐步指南,將幫助你避免偽 CAPTCHA 欺騙

  1. 切勿點擊陌生 CAPTCHA 提示的「允許」
  2. 避免複製貼上奇怪的指令
  3. 仔細檢查網站URL
  4. 保持瀏覽器和安全軟體更新
  5. 如果感覺到任何可疑情況請關閉分頁