A spearphishing attack that lasted a single day targeted members of the Ukrainian regional government administration and organizations critical for the war relief effort in Ukraine, including the International Committee of the Red Cross, UNICEF, and various NGOs. Dubbed PhantomCaptcha, the one-day campaign attempted to trick victims into running commands used in ClickFix attacks, disguised as Cloudflare CAPTCHA verification prompts, to install a WebSocket Remote Access Trojan (RAT). SentinelLABS, the threat research division at SentinelOne, says that the campaign started and ended on October 8, and that the attacker spent significant time and effort to set up the necessary infrastructure, as some domains used in the operation were registered at the end of March. The attacks started with emails impersonating the Ukrainian President’s Office, carrying malicious PDF attachments that linked to a domain impersonating the Zoom (zoomconference[.]app) communication platform. When clicking on the fake Zoom conference link, visitors saw an automated browser check process before redirecting to the communication platform. During this stage, a client identifier is generated and passed to the attacker's server over a Websocket connection. "If the WebSocket server responded with a matching identifier, the victim’s browser would redirect to a legitimate, password-protected Zoom meeting," SentinelLABS' analysis showed. According to the researchers, this path likely led to the threat actor en...
PhantomCaptcha ClickFix attack targets Ukraine war relief orgs
BleepingComputer
·Bill Toulas
·Published Oct 22, 2025
·Updated
Affected Software
2 affected components
Cloudflare Cloudflare
Zoom Zoom
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a spearphishing attack targeting Ukrainian war relief organizations.
2
What security implications are discussed in the article?
The attack highlights vulnerabilities in communication systems used by organizations aiding Ukraine during the conflict.
3
What organizations were specifically targeted in the attack?
The attack targeted members of the Ukrainian regional government and organizations like the International Committee of the Red Cross.
4
Which software products are affected by the attack?
The affected products include Cloudflare and Zoom.
5
What was the duration of the spearphishing attack mentioned in the article?
The spearphishing attack lasted a single day.