BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Hackers Use Fake CAPTCHAs, USBs to Spread CORNFLAKE and XMRig

Fake CAPTCHA Pages Used to Deploy CORNFLAKE.V3 Backdoor in Global Malware Campaigns

  • Attackers use fake CAPTCHA pages to lure users into infecting systems with a backdoor named CORNFLAKE.V3.
  • The threat group tracked as UNC5518 sells access which other groups monetize through additional Malware deployment.
  • CORNFLAKE.V3 is capable of executing multiple payloads, gathering data, and maintaining persistence on hosts.
  • Malware campaigns also use infected USB drives to spread cryptocurrency mining software like XMRig.
  • Disabling the Windows Run dialog and monitoring suspicious script execution may help reduce risk of infection.

A new cyberattack method uses fake CAPTCHA pages to spread a versatile backdoor named CORNFLAKE.V3, according to research published on August 21, 2025. The campaign, observed by Google-owned Mandiant, targets users worldwide by exploiting social engineering tactics to gain unauthorized access and monetize infected systems.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The attack group, known as UNC5518, tricks users into running a malicious script by prompting them to copy and execute a command via the Windows Run dialog box. Mandiant identified two other groups, UNC5774 and UNC4108, that utilize the access provided by UNC5518 to launch further attacks, including payload delivery and system control tools.

The infection begins when a user interacts with a manipulated search result or ad, leading to a fake CAPTCHA page. After the user executes the supplied script, the computer downloads additional malware. The CORNFLAKE.V3 backdoor then checks if it is running in a virtual machine and establishes communication with external servers, often routing traffic through Cloudflare tunnels to avoid detection.

CORNFLAKE.V3 has versions in JavaScript and PHP. It delivers various types of files, including executables and PowerShell scripts, and collects basic system information. Persistence is achieved through changes to the Windows Registry. Delivered payloads can include utilities for network reconnaissance, credential harvesting, and another backdoor called WINDYTWIST.SEA, which provides remote shell access.

A related campaign continues to use infected USB drives to install cryptocurrency miners, like XMRig for Monero and other coins, since September 2024. Attackers trick users into running shortcuts on compromised drives, which initiates a chain of scripts and payloads with tools such as DIRTYBULK, CUTFAIL, and PUMPBENCH.

- Advertisement -

Researchers recommend disabling the Windows Run dialog, conducting regular security awareness drills, and improving monitoring for suspicious PowerShell and script execution. Mandiant notes that initial access through USB drives remains highly effective due to its low cost and ability to bypass many standard defenses. Full details and reports are available in Google’s threat blog and the community blog.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SEC seeks clarity on crypto, bonds in OTC rule change

The SEC has proposed to amend Rule 15c2-11 to clarify it applies only to...

Ex-Deputy Gets 5+ Years in Crypto “Godfather” Extortion

A former Los Angeles County sheriff’s deputy was sentenced to over five years in...

OpenSea Delays $SEA Token Launch, Cites Market Woes

OpenSea indefinitely postponed the launch of its SEA token, announced in October, due to...

Pokémon Go Scans Power New Delivery Robot Navigation

Niantic Spatial is partnering with Coco Robotics to power navigation for autonomous delivery robots...

Micron Unveils Next-Gen HBM4, Boosts AI Memory Speeds

Micron Technology has begun volume shipments of its new HBM4 memory, designed for NVIDIA's...

Must Read

How Much Money Do You Need To Start In Crypto?

TL;DR -If you are wondering How Much Money Do You Need To Start In Crypto, note that is less than you are probably thinking....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading