Bad actors and hackers have identified a loophole that allows them use fake CAPTCHA pages to trick Windows users into launching “Stealthy StealC Information Stealer” malware.
According to security sleuths at LevelBlue, “StealC exfiltrates browser credentials, cryptocurrency wallets, Steam accounts, Outlook credentials, system information, and screenshots to a command-and-control (C2) server using RC4-encrypted HTTP traffic.”
The social engineering campaign leverages fake CAPTCHA verification pages on compromised websites, which feature realistic Cloudflare-style security checks. As a result, unsuspecting Windows users end up manually executing malicious PowerShell commands disguised as routine verification (via TechRepublic).
I’ve never fully understood the true essence of a CAPTCHA. Yet, as we move deeper into the AI era, proving that an online user is human rather than a bot has become increasingly important. CAPTCHAs are designed to safeguard users by preventing spam and blocking password‑cracking attempts.
How bad actors use the StealC campaign

As a general rule of thumb, it’s always encouraged to be mindful of the websites you’re visiting to reduce security risks and threats from bad actors. However, attackers are increasingly cunning and are using more sophisticated techniques.
For instance, the StealC social engineering campaign involves unsuspecting Windows users visiting a usually legitimate website that’s already been compromised by hackers, who embed malicious JavaScript code to load a fake CAPTCHA page, which resembles Cloudflare’s verification UI.
However, instead of presenting users with visual tests, the fake CAPTCHA page requests the user to press Windows Key + R, then Ctrl + V, and finally hit the Enter key as part of the verification process.

