BrianKrebs on Nostr: Called it. Wrote this back in Sept. 2024, about a clever Windows Powershell phishing ...
Called it. Wrote this back in Sept. 2024, about a clever Windows Powershell phishing scam that was targeting developers at the time. It uses a fake CAPTCHA that asks visitors to distinguish themselves from bots by pressing a combination of keyboard keys that causes Microsoft Windows to download password-stealing malware. Everyone said, bah, devs will never fall for this. Maybe, I said, but your average user would for sure.
Judging from the number of recent media reports, it appears this one is pretty widespread at the moment.
https://krebsonsecurity.com/2024/09/this-windows-powershell-phish-has-scary-potential/
Published at
2025-03-14 13:18:36Event JSON
{
"id": "195c51a11e73a3643eafa5b79e83ea04923a306a4b72d0a3297ce1a82366d703",
"pubkey": "1a5ac5b37984c5e37a11bc914029a81f025326ea7950c9475d9a3f21a494cb56",
"created_at": 1741958316,
"kind": 1,
"tags": [
[
"imeta",
"url https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/160/976/012/619/024/original/7660ca7800fa00a1.png",
"m image/png",
"dim 1194x679",
"blurhash UUIY5@D%4n?bIUxu-;IUjst7xuRi~qM{IAxu"
],
[
"proxy",
"https://infosec.exchange/users/briankrebs/statuses/114160980257383048",
"activitypub"
]
],
"content": "Called it. Wrote this back in Sept. 2024, about a clever Windows Powershell phishing scam that was targeting developers at the time. It uses a fake CAPTCHA that asks visitors to distinguish themselves from bots by pressing a combination of keyboard keys that causes Microsoft Windows to download password-stealing malware. Everyone said, bah, devs will never fall for this. Maybe, I said, but your average user would for sure.\n\nJudging from the number of recent media reports, it appears this one is pretty widespread at the moment.\n\nhttps://krebsonsecurity.com/2024/09/this-windows-powershell-phish-has-scary-potential/\n\nhttps://media.infosec.exchange/infosec.exchange/media_attachments/files/114/160/976/012/619/024/original/7660ca7800fa00a1.png",
"sig": "de00856938eaefc2f5dd5e0db5ad4bc4f6e1c11a5f5c62d44e8c906e6ce05e27cef014a394559475435424908b9dc6edd02c98bae259b0fe5d8bdaff622f0ebc"
}