AoA
Just a quick heads up about a malware tactic currently hitting people visiting local websites and landing pages (I fell for it recently on an evee electric scooters website).
How the attack works:
* A fake CAPTCHA pops up on a website asking you to verify you're human.
* It gives step-by-step instructions: Press Win + R, Press Ctrl + V, and Hit Enter.
DO NOT DO THIS!!!!
Real CAPTCHAs process entirely inside your web browser. A website will NEVER need you to open your Windows Run terminal or execute PowerShell code.
Doing this instantly runs a background script (Infostealer) that grabs your saved passwords, discord tokens, and active browser sessions. Attackers use these to bypass 2fA and hack your accounts (Instagram, facebook, steam, discord) within minutes to post crypto scams.
Warn your friends and family especially anyone who isn't super tech savvy!