Automatically translated.View original post

FTC warns users to beware of fake Captcha

The FTC warns users to beware of fake Captcha that can lead to malware addiction.

According to a report by the website Techlicious, the Federal Trade Commission has issued a warning to people to be wary of fake Captcha that can lead to malware installation, in which malware from this fake Captcha campaign can lead to the theft of key information, passwords, financial information, and digital assets in Cryptokerrency, the campaign was first detected in 2024. 2567), which will focus primarily on tackling the Windows operating system group of users, before later spreading to the macOS group of users.

The way it works is simple. Hackers will trick the victim into a fake website link that was created or a hacked website. On the website, after the victim has visited for a while, it will appear as a captcha security check screen. On Captcha, it will deceive the victim using the Windows system to launch the Run feature via the Windows + R button. After that, the victim will place the command code on Run via the Ctrl + V button. The code has been quietly copied to the Clipboard since the victim entered the screen. In the first place, the code leads to running PowerShell scripts to download and ultimately install malware. That method can be called a ClickFix method.

The FTC advised the victim to disconnect to the Internet immediately to disrupt the malware installation process and then scan the machine with software like Anti-Virus. After the machine is clean, change all passwords and enable double authentication (2FA or 2 Factors Authentication) for security purposes. The FTC has said that the organization will continue to study and investigate the malware release campaign.

# Trending # Lemon 8 Howtoo # lemon 8 diary # FTC # freedomhack

7/3 Edited to

... Read moreจากประสบการณ์การใช้งานอินเทอร์เน็ตและการพบเจอปัญหาเกี่ยวกับมัลแวร์ ฉันได้เรียนรู้ว่าการรับมือกับ Captcha ปลอมเป็นสิ่งที่สำคัญมากในยุคนี้ โดยเฉพาะอย่างยิ่งเมื่อ FTC ได้ออกมาเตือนเกี่ยวกับการหลอกลวงที่แฮกเกอร์ใช้วิธีการจำลองหน้าจอ Captcha ปลอมเพื่อดึงให้ผู้ใช้งาน Windows กดคำสั่ง Run และวางโค้ดที่จะรัน PowerShell สคริปท์เพื่อติดตั้งมัลแวร์ ซึ่งวิธีการนี้เป็นเทคนิคที่น่ากลัวเพราะผู้ใช้อาจไม่ทันได้คิดว่านี่คือกับดัก นอกจากนี้ ในช่วงที่มีข่าวแพร่หลายเกี่ยวกับมัลแวร์จาก Captcha ปลอม สิ่งที่ฉันมักแนะนำเพื่อนหรือคนรอบตัวคืออย่ารีบคลิกหรือทำตามคำสั่งใด ๆ ที่ได้รับจากหน้าจอไม่คุ้นเคย โดยเฉพาะคำสั่งที่ต้องเปิดโปรแกรมด้วยปุ่ม Windows+R หรือเรียกใช้ฟีเจอร์ Run จากนั้นให้ตรวจสอบ URL ของเว็บไซต์และความถูกต้องก่อนทุกครั้ง หากพบว่ามีลักษณะที่ไม่น่าเชื่อถือควรปิดเว็บไซต์ทันทีและไม่ควรคัดลอกหรือนำโค้ดใด ๆ มาวาง สำหรับการป้องกันที่ได้รับการแนะนำโดย FTC อย่างการตัดการเชื่อมต่ออินเทอร์เน็ตเมื่อสงสัยว่าติดมัลแวร์แล้ว และสแกนด้วยแอนตี้ไวรัสที่เชื่อถือได้ รวมถึงการเปลี่ยนรหัสผ่านและเปิดใช้งานการยืนยันตัวตนสองขั้นตอน (2FA) นั้น ฉันพบว่าช่วยลดความเสี่ยงของการถูกแฮกได้อย่างมาก รวมถึงการรู้จักอัปเดตซอฟต์แวร์และระบบปฏิบัติการให้ทันสมัยอยู่เสมอก็ช่วยป้องกันช่องโหว่ที่แฮกเกอร์อาจใช้ประโยชน์ได้ด้วย สรุปแล้ว การเข้าใจถึงเทคนิคที่แฮกเกอร์ใช้ เช่น การแสดงข้อความ "Robot or human? Check the box to confirm that you're human." หรือขั้นตอนการหลอกให้กดปุ่ม Windows + R แล้ววางโค้ดนั้น เป็นความรู้ที่ช่วยให้เราป้องกันตัวเองได้ดีขึ้นในยุคที่ภัยไซเบอร์กำลังเพิ่มขึ้นทุกวัน ใครที่ยังไม่เคยเจอเหตุการณ์แบบนี้ ก็ควรหาเวลาทำความเข้าใจและติดตั้งแอนตี้ไวรัสที่น่าเชื่อถือเพื่อเสริมเกราะป้องกันในระบบของตนเอง