Phishing pages leverage CAPTCHAs to fool users, evade detection

Phishing pages leverage CAPTCHAs to fool users, evade detection

Cyberattackers targeting the hospitality industry were recently observed using a phishing page that featured CAPTCHA technology as a way to elude detection, as well as to give potential victims a false sense of security that the malicious site was legit.


The scam was revealed yesterday in a blog post from Menlo Security – the latest in a string of reports this year from security companies that have warned of this social engineering and evasion technique. Fortunately, experts say that phishing-site CAPTCHAs sometimes offer visitors – especially attentive ones who are trained in security awareness – certain visual and contextual clues that something is amiss.


A CAPTCHA (sometimes referred to as a reCAPTCHA – a version developed by Google) is a test placed on websites to determine whether a visitor is a genuine human or an unwanted bot. Generally, users are asked to check a box or click on a series of images that contain a specified object, like a traffic light or bicycle.


But Menlo Security and other cybe ..

Support the originator by clicking the read the rest link below.