tech ๐ Fake CAPTCHA malware shuts down endpoint security
Hackers are deploying malware by tricking users into running a malicious PowerShell command via fake CAPTCHA pages. This attack chain uses the ErrTraffic platform, delivered through compromised WordPress sites, as seen in late July 2026. The malware, Cruciferra, can terminate 145 AV and EDR processes, including Microsoft Defender, using a BYOVD technique. This method bypasses traditional download filters by relying on social engineering to execute the payload. Defenders must treat these fake verification pages as malicious by default to counter this threat. ๐ก๏ธ