Phishing

reCAPTCHA Phish – A Dive Into Social Engineering Tactics

This is small harness to recreate the social engineering and phishing lure recently seen in the wild around August/September 2024.

The Lure In The Wild

Originally seen with the guise “Verify you are human”, the attack vector being copy and paste.

It literally instructs the user to open the Windows Run dialog box with the hotkey Win+R, and have them paste in a malicious command with Ctrl+V that the web browser has premptively copied into their clipboard.

Really all you need is index.html. It includes the CSS and JavaScript in a single file for ease of use, but might need further customization to change the command that is ran (see the JavaScript at the end of the showVerifyWindow function).

This can be used as a standalone file and a run any local command, but to get a bit more flexibility with code execution, this repository includes a sample HTA file recaptcha-verify for an innocent proof of concept of popping open the Windows calculator application.

This secondary HTA file would mean it needs to be hosted server-side, or have some other backing infrastructure to offer the payload.

For quick local testing, I literally just used python -m http.server 8000.

The HTA file also gives you an opportunity for more convincing charade, too, potentially with a window that pops up to “try and connect to the reCAPTCHA servers”, but state that it fails and prompt the user to do it all over again. 🤪 (Extra callbacks, anybody?)

So this recreation has some extra perks:

  • Looks and feels like “real” reCAPTCHA (image from the official Google site)
  • Validation in the Run box to “hide” the command (✅ “I am not a robot – reCAPTCHA Verification ID: 7624”)
  • Disabled “Verify” button to further encourage users to complete the copy-paste steps. 🚫
  • Fleshed out phish with the follow-up windows “failed to verify”
  • Clears the clipboard so the payload command is removed.
Varshini

Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Recent Posts

sort Command in Linux: Sort Text, Numbers, Columns, and More

The sort command in Linux reads lines from files or standard input and writes them to standard…

24 hours ago

wall Command in Linux: Broadcast Messages to Logged-In Users

The wall command in Linux sends a message to the terminals of all currently logged-in users. The…

1 day ago

journalctl Command in Linux: Query and Filter System Logs

journalctl queries logs collected by systemd-journald, the systemd logging daemon. It gives you structured access to kernel…

1 day ago

stat Command in Linux: View File and Filesystem Metadata

The stat command in Linux displays detailed metadata about files and filesystems. Where ls gives a condensed summary suitable…

1 day ago

groupadd Command in Linux: Create Groups and Set GID Options

In Linux, groups organize user accounts and define shared access to files and resources. Every…

2 days ago

touch Command in Linux: Create Files and Update Timestamps

The touch command in Linux does two things: it creates new empty files, and it updates the…

2 days ago