• News/
  • https://www.bleepingcomputer.com/news/security/phantomcaptcha-clickfix-attack-targets-ukraine-war-relief-orgs/

PhantomCaptcha ClickFix attack targets Ukraine war relief orgs

BleepingComputer
·
Bill Toulas
·
Published Oct 22, 2025
·
Updated

A spearphishing attack that lasted a single day targeted members of the Ukrainian regional government administration and organizations critical for the war relief effort in Ukraine, including the International Committee of the Red Cross, UNICEF, and various NGOs. Dubbed PhantomCaptcha, the one-day campaign attempted to trick victims into running commands used in ClickFix attacks, disguised as Cloudflare CAPTCHA verification prompts, to install a WebSocket Remote Access Trojan (RAT). SentinelLABS, the threat research division at SentinelOne, says that the campaign started and ended on October 8, and that the attacker spent significant time and effort to set up the necessary infrastructure, as some domains used in the operation were registered at the end of March. The attacks started with emails impersonating the Ukrainian President’s Office, carrying malicious PDF attachments that linked to a domain impersonating the Zoom (zoomconference[.]app) communication platform. When clicking on the fake Zoom conference link, visitors saw an automated browser check process before redirecting to the communication platform. During this stage, a client identifier is generated and passed to the attacker's server over a Websocket connection. "If the WebSocket server responded with a matching identifier, the victim’s browser would redirect to a legitimate, password-protected Zoom meeting," SentinelLABS' analysis showed. According to the researchers, this path likely led to the threat actor en...

Read full article

Affected Software

2 affected components
Cloudflare Cloudflare
Zoom Zoom
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a spearphishing attack targeting Ukrainian war relief organizations.

2

What security implications are discussed in the article?

The attack highlights vulnerabilities in communication systems used by organizations aiding Ukraine during the conflict.

3

What organizations were specifically targeted in the attack?

The attack targeted members of the Ukrainian regional government and organizations like the International Committee of the Red Cross.

4

Which software products are affected by the attack?

The affected products include Cloudflare and Zoom.

5

What was the duration of the spearphishing attack mentioned in the article?

The spearphishing attack lasted a single day.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203