National Digital Agency warns: Fake "I am not a robot" screen used to take over computers
The National Digital Agency warns of the ShadowCaptcha campaign identified in 45 countries, including Israel. Legitimate websites that have been breached display a fake verification that asks users to paste a command into their computer.

The National Digital Agency warns this evening (Thursday) about the intensification of the international attack campaign ShadowCaptcha, in which fake "I am not a robot" screens are displayed to users to trick them into executing malicious commands themselves. According to the announcement, attack attempts have been identified in 45 countries, including Israel, the USA, Sweden, Australia, and others. Hundreds of websites have been breached worldwide, but government systems have not been affected and are operating as usual.
"The ShadowCaptcha campaign illustrates how attackers are refining their methods of operation. They are turning the familiar 'I am not a robot' screen into a trap, and are now also using blockchain infrastructure to transmit malicious code and make it harder to detect. It is important for the public to remember a simple rule: a real CAPTCHA test will never ask you to open a window on your computer or paste a command — act according to the instructions of the National Digital Agency," said Brigadier General (res.) Nati Cohen, Director General of the National Digital Agency.
In the Government Cyber Defense Unit (Yahav) at the National Digital Agency, they explain that as part of the campaign, attackers display a fake verification screen even on legitimate websites that have been breached, and instruct the user to copy and paste a command into a window on the computer. Following the instructions downloads malicious software that allows attackers to take over the computer, steal information, mine digital currencies, and demand ransom.
In the new format observed in recent days, the attackers are also using public blockchain networks as a conduit for transmitting the malicious code. According to the National Digital Agency, this method makes it difficult for security systems to identify and remove the threat.
The agency emphasizes that a real CAPTCHA test is performed only within the browser, by checking a box or selecting images. As part of such a test, the user is not supposed to open a command window on the computer, press key combinations, or paste text. The affected sites include e-commerce, health, finance, and tourism sites; the names of the sites were not published because work is still underway to harden their security.





