In this page, we document cases of CAPTCHA-cloaked phishing webpages in-the-wild.
Target: Commonwealth Bank (AUS)
Category: Banking/Finance
CAPTCHA Used: reCAPTCHAv2
Indicators of Compromise:
hxxps://mycomsec-verify.com/
Target: PayPal (International)
Category: Banking/Finance
CAPTCHA Used: reCAPTCHAv2
Indicators of Compromise:
hxxps://accountlogin.lhr.rocks/reco.html.php
hxxps://paycustomerportal.lhr.rocks/
login.html.php
Target: Microsoft (International)
Category: Technology
CAPTCHA Used: reCAPTCHAv2
Indicators of Compromise:
hxxps://yousitesureonlineverification.com/
Target: Apple (International)
Category: Technology
CAPTCHA Used: reCAPTCHAv2
Indicators of Compromise:
hxxps://auth1icl0ud.info/
Target: Canada Post (CAN)
Category: Logistics
CAPTCHA Used: reCAPTCHAv2
Indicators of Compromise:
hxxps://canadaposte-tracking.com/
hxxps://can-postschedule.com/
hxxps://canadaposte-tracking.com/
hxxps://post-ca-mail.info/
hxxps://postcan-deliveryreschedule.com/
hxxps://postecanada-tracking.com/
Target: Royal Mail (GBR)
Category: Logistics
CAPTCHA Used: reCAPTCHAv2
Indicators of Compromise:
hxxps://royalmail.failed-deliveries.com/
hxxps://www.royalmail.failed-delivery0.com/
hxxps://failed-delivery0.com/
hxxps://royalmail.failed-delivery0.com/
Target: UPS (USA)
Category: Logistics
CAPTCHA Used: hCAPTCHA
Indicators of Compromise:
hxxps://www.distribution-ups.online/
hxxps://delivery-ups.net/
hxxps://upspostsav.com/
hxxps://login-trackups.com/
antibots/untrusted/index.php
hxxps://colis-ups-suivi.com/app/index.php?userid={UUID}
hxxps://ups-website.online/
Target: DHL (International)
Category: Logistics
CAPTCHA Used: reCAPTCHAv2
Indicators of Compromise:
hxxps://mytrackdrop.info/
antibots/untrusted/index.php
hxxps://csomag-atiranyitas.info/
antibots/untrusted/index.php
Target: Bet365 (International)
Category: Entertainment/Gambling
CAPTCHA Used: slider (custom)
Indicators of Compromise:
hxxps://ldp36.ydwghi.xyz/
hxxps://ldp42.ydwghi.xyz/
hxxps://ldp45.ydwghi.xyz/