...
Saturday . 10 January . 2026
Breaking Update

Israel National Digital Agency Uncovers Global Cyberattack Campaign “ShadowCaptcha”

Israel National Digital Agency uncovers ongoing global cyberattack campaign "ShadowCaptcha" using fake CAPTCHA pages to execute malicious commands on

Israel National Digital Agency Breaking News

 

In August 2025, Israel National Digital Agency researchers uncovered an ongoing large-scale cybercrime campaign leveraging a ClickFix technique. The campaign uses a fake Cloudflare or Google CAPTCHA page to trick victims into executing malicious commands via compromised WordPress websites.

Retrospective analysis indicates the campaign has been active for at least the past year with the potential to impact thousands of organizations worldwide. Analysis uncovered over 100 compromised WordPress sites injected with malicious JavaScript redirecting to attacker-controlled infrastructure, and hundreds of malware samples spanning multiple families and variants.

The campaign, which we have dubbed ShadowCaptcha, blends social engineering, living-off-the-land binaries (LOLBins), and multi-stage payload delivery to gain and maintain a foothold in targeted systems. The ultimate objectives of ShadowCaptcha are collecting sensitive information through credential harvesting and browser data exfiltration, deploying cryptocurrency miners to generate illicit profits, and even causing ransomware outbreaks. This combination of tactics underscores its nature as an opportunistic financially motivated operation, blending social engineering, stealthy persistence, and monetization through both data theft and cryptomining.

If undetected, ShadowCaptcha can result in prolonged unauthorized access to internal systems, sustained cryptomining that degrades performance and increases operational costs, and large-scale exfiltration of sensitive data that could lead to reputational damage, regulatory penalties, and financial losses. The opportunistic nature of this campaign means that any internet-facing organization is a potential target, regardless of size or sector.

Given its scale and adaptability, we recommend creating detection and prevention rules targeting the TTPs detailed in this report, alongside awareness training for end-users to recognize and avoid the broader ClickFix social engineering technique, to reduce risk and prevent future incidents

 

author avatar
Israel National Digital Agency
Live Breaking Updates

Breaking News Coverage

Real-time breaking news coverage from Israel and the Middle East. Stay informed with the latest developments as they happen.

Saturday, 10 January 2026 Updated continuously
Crime 2 days ago

President of Israel Holds Emergency Conference on Crime in Negev Arab Communities

Israeli President Isaac Herzog convenes Negev leaders for an emergency conference addressing the alarming rise in crime and violence, emphasizing the urgent.

Israel Society 2 days ago

Programs in Artificial Intelligence Training Being Offered to Israeli Reservists

Israel launches AI leadership training for 750 reservists, aiming to bridge wartime knowledge gaps and enhance high-tech industry innovation and productivity.

Disasters 2 days ago

Israel Allocates Millions for Climate Change Preparedness in Local Arab Areas

Israel allocates 16.7 million Shekels ($5.2M) for climate change preparedness in 11 Arab local authorities, including Rahat and Umm el-Fahm, to combat heat.

Business 2 days ago

Israeli Crime Boss Nidal Abu Latif and Others Indicted on Charges Including Extortion and Money Laundering

Israeli crime boss Nidal Abu Latif and 10 others indicted on charges including extortion and money laundering. Covert investigation uncovers offenses against a.

Israel Society 2 days ago

Israel Calls on Its Youth to Join Global Fight Against Anti-Semitism and to Strengthen Ties with World Jewry

Israel calls on youth to join national service fighting anti-Semitism and strengthening ties with world Jewry. Make a real impact in Jerusalem and globally.

Disasters 2 days ago

President Herzog Reopens Kindergarten Destroyed by Hezbollah Rocket at Kibbutz Manara

President Herzog inaugurated a rebuilt kindergarten at Kibbutz Manara, destroyed by Hezbollah rockets, marking a symbol of resilience and renewal for northern.

Crime 2 days ago

Three Israelis Arrested for Destroying Palestinian Property in Samaria

IDF arrests three Israelis for destroying Palestinian property and assaulting a Palestinian near Tulkarm, Samaria, injuring two. Security forces condemn.

Economy 2 days ago

Shekel Exchange Rates End of Day Thursday, January 8, 2025

Bank of Israel sets end-of-day Shekel exchange rates for Thursday, Jan. 8, 2025. See US Dollar, Euro, GBP, and Yen rates, with daily changes against the Israeli.

Politics 2 days ago

Ethiopian Immigrant Program Report 2023-2024

Israel's Prime Minister's Office releases its 2023-2024 report on the Ethiopian Immigrant Integration Program, detailing progress in education and employment.

Politics 2 days ago

PM’s Office: Ethiopian Immigrant Integration Report

Israel's PM's Office publishes 2023-2024 report on Ethiopian immigrant integration, detailing achievements in education, employment, and community resilience.