peta baru sumber kejahatan siber dunia ini daftar negaranya 1762251132866 169 (1) Mitra IT | Your Trusted & Reliable Software Solutions

Beware of Filling in “I’m Not a Robot,” Your Account Can Be Drained Instantly

Jakarta, CNBC Indonesia A fraudulent method uses fake captchas to lure victims. This method can result in financial loss and the loss of sensitive information.

Captcha itself is a security feature used on websites or applications. It appears to verify whether a user is a real human or an automated bot.

Kaspersky’s findings reveal a modus operandi targeting Windows PC users, occurring while browsing. Potential victims encounter an ad that covers the entire screen and attempt to close it.

However, clicking on the ad redirects to a fake Captcha page and a fake Chrome error message. This is designed to trick users into downloading malware known as a stealer.

“The criminals purchased multiple ad slots, and if users saw these ads and clicked on them, they would be redirected to a malicious website. This new method involves a significantly expanded distribution network and the introduction of new attack scenarios that reach more victims,” ​​said Vasily Kolesnikov, a security expert at Kaspersky, as quoted in a written statement on its official website, Tuesday (June 22, 2026).

“Now, users can be tricked by fake Captcha prompts or Chrome webpage error messages, thus becoming victims of theft. Corporate and individual users should be careful and think critically before following any suspicious prompts they see online,” he added.

Clicking the “I’m not a robot” button in the captcha will copy a malicious script to the clipboard. The victim is asked to paste it into the terminal, which turns out to be a way to download it.

and launches trojans like Lumma.

This malware steals sensitive information, such as crypto assets, cookies, and password manager data. It can also obtain screenshots, remote access service credentials, and control the victim’s device by downloading remote access tools.

This incident targeted users in several countries, including Brazil, Spain, Italy, and Russia.

This incident targeted many users in various countries, including Brazil, Spain, Italy, and Russia.

According to Kaspersky Telemetry data, more than 140,000 malicious ad incidents were discovered between September and October 2024. More than 20,000 users were redirected to fake pages containing malicious scripts.

Users can protect themselves by remaining cautious and avoiding following suspicious commands in their browsers. This is especially important when clicking on ads on websites.

SOURCE : CNBC INDONESIA