$ 44.92 € 50.29 zł 11.45
+12° Kyiv +11° Warsaw +24° Washington

The State Special Communications Service detected the spread of a virus disguised as the "I'm Not a Robot" verification

UA NEWS 06 October 2026 14:21
The State Special Communications Service detected the spread of a virus disguised as the "I'm Not a Robot" verification

CERT-UA, the national response team for cyber incidents, cyberattacks, and cyber threats operating under the State Special Communications Service, has detected a new large-scale campaign to spread malware.

In September 2026 alone, CERT-UA specialists recorded over 100 compromised websites. Hackers injected malicious JavaScript code into the compromised sites.

A distinctive feature of this campaign is that the attackers use legitimate and well-known websites. They compromise the sites and make minor changes that can go unnoticed by owners and visitors for a long time.

Once a user visits a compromised site, they are shown a fake Cloudflare verification page.

Under the guise of a standard “I’m not a robot” verification, the user is prompted to copy and execute a specific command. To do this, the attackers may ask the user to use the Win+R shortcut, the command prompt, or PowerShell.

If the user executes the suggested command, malware is downloaded and installed on their computer.

However, the malicious page has additional restrictions. It is displayed only to Windows users who have navigated to the site from search engines, including Google, DuckDuckGo, and others. Additionally, such a page appears no more than twice within a 12-hour period.

CERT-UA experts emphasize that legitimate verification systems never require users to open the command prompt or PowerShell and execute unknown commands.

“Experts emphasize that no legitimate verification (CAPTCHA, Cloudflare, etc.) ever requires you to press the Win+R key combination, open the command prompt or PowerShell, or enter and execute any commands,” the warning states.

CERT-UA also urges users:

“If you see such a request, close the page immediately, even if it’s a website you’re familiar with.”

Once a computer is infected, the malware silently installs an extension in the victim’s browser disguised as “Microsoft Office Word Editor.”

According to CERT-UA, this tool can steal usernames, passwords, and browsing history. Additionally, it allows attackers to remotely control the infected computer.

Thus, a seemingly ordinary “I’m not a robot” verification can lead not only to the device being infected but also to the theft of account credentials and hackers gaining remote access to the system.

To strengthen business security, system administrators are advised to take additional measures.

In particular, experts advise disabling the ability for regular users to open the “Run” dialog using Win+R, as well as restricting the installation of any MSI packages without administrator privileges.

CERT-UA emphasizes that even if a suspicious prompt appears on a well-known or familiar website, users should not execute the suggested commands. This could be a sign that the site has been compromised and an attempt to install malicious software.

The State Special Communications Service reported this dangerous scheme.

Earlier, Ukraine’s government computer emergency response team, CERT-UA, detected a new large-scale phishing attack. This time, the attackers’ main targets were Ukrainian military personnel, government employees, and staff at critical infrastructure facilities. 

Read us on
Download our app