The WordPress Trojan Horse: How a Fake CAPTCHA Drained Crypto Wallets for Months

CryptoWhale
Flash News

31,000 screenshots. 700+ compressed archives. Nearly 2,000 compromised WordPress sites. One fake CAPTCHA.

This is not a drill. This is the attack chain that has been running since May, silently harvesting cryptocurrency wallet recovery phrases from Windows users who thought they were proving they weren't robots.

Check Point Research broke the story on August 21. But the operation is still warm. 6,000+ IPs have been hit. The C2 infrastructure is intact. The malware continues to spread over networks and USB devices.

Most of us were trained to spot phishing. We look for weird URLs, misspelled domains, emails from "Coinbase Support." This attack is a generation ahead. It uses the one thing every modern user trusts without question: the CAPTCHA image.

Here is the anatomy of the kill chain. You search for something mundane. Maybe a template for a resume. Maybe a movie script. The search engine directs you to a WordPress page that looks clean. It loads. You see a fake CAPTCHA verification. The system asks you to click to prove you are human. A command pops up. It's a PowerShell script. The instructions say: "Press Windows+R, paste the script, and press Enter".

No malicious link. No downloaded. Just the user copying and pasting text that what the website instructed.

This is social engineering on the next level. The attacker isn't expecting you to click a bad link. They're telling the victim to hand them the keys. It is an old school ransomware scheme with a modern twist: targeted especially to the metadata that moves crypto: your wallet recovery phrase.

Once the PowerShell executes, the malware goes hunting. It pulls credentials from browsers. It also scans for TronLink and other crypto wallet extensions. It is capturing screenshots. It is recording keystrokes. It is watching how you interact with your accounts.

The recovery phrases are then sent to the C2 server. From there, all your funds are gone.

Several months ago, I built a script to track validator queues during the Ethereum Merge. That same pattern of looking across web server logs is here. The data from this campaign is broad. It shows 3000+ ZIPS with detailed screenshots. The level of this collection indicates the attackers are running an automated surveillance apparatus, not just a smash-and-grab. They might not lazy drain the wallets. They wait. They watch. They determine which wallets have the highest value total. Then they attack.

The infrastructure the attackers used is sloppy. It is brilliant. They planted malware on hundreds of WordPress sites. They are using these sites as Command and Control (C2) networks. The same sites are also their malware repositories. The same sites are their data storage for exfiltrated files.

WordPress has a real problem with updating themes. A whole ecosystem of commerce has grown around template plugins. When a plugin is abandoned, its vulnerabilities linger. The attackers exploited this to install a loader via a WordPress site to the internet. They are using trusted infrastructure to build a botnet.

There's something unique about the attackers' cowardice. In late July, Check Point researchers saw the C2 panel routing from the malware. They looked at 31,000 screenshots submitted by attackers's own victims. But they also noticed that the attackers should have infected themselves. Screenshots from analysts during their analysis of the malware showed the command line in the test console. The attacker captured some of the screenshots from their own console because of screen transmission protection rules.

Trying to track them just ensures it is easier to trace them.

Imagine this: an attacker monitoring your screen while you hold your military on it. There is a command to protect. I usually admonish You use hardware wallets. You secure your seed from the network socket. What you should also have considered is your browser session exposure.

During an incident such as this scam, this Crypto's own wallet mnemonic capture has been captured by a system outage. If you type your phrase into a website, this is another risk vector. This brings me a surprise. All smart contract security of the chain is only as strong as the machine where the funds are accessed from.

In 2022, I watched the FTX collapse. Users sought help for "how to claim crypto". The situation created a problem to give a fast-fix. I wrote 15 guides for them in 48 hours.

Now, this new bull cycle is releasing the same panic. It is not around a centralized exchange going bankrupt. It is about a decentralized wallet, all balances are drained. The user only has a screenshot of a ledger.

There are several warnings across the chain data:

  1. The turning point is 30,000 screenshots. It is a treasure trove for the attacker. They have a view of every wallet they have
  1. The next sequence is the cleanup. Attackers are not sitting in the vault. They will empty it after. But they have been detected on the exact moment after?
  1. The regulator is not going to help. Using a private wallet recovery phrase in a smart contract is irreversible. No courts can reverse it.

Now a bad thing for crypto traders is that the power is out in the rest of the market. On the opposite end of the bear market, trade volumes are down. But in a bear market, operators getting robbed is not an investment topic. It is a way to survive.

When you use the wrong economic model to protect your fund, the bear cycle is about cutting off your burn. This applied to code garbage projects. But it also applies to your digital shelf life.

Brute-force attack advice does not fully solve this. You can only need Layer 2 in your life if that avoids 99% of DA attacks. So is this a fix to avoid 99% of attack usually?

PowerShell attacks sim for old methods. The basic rule is:

  • Do not paste any commands into the run box or terminal from a website. Do not paste it even as an Admin.
  • Use a hardware wallet for anything that is above your investing budget.
  • Check the websites reputation before interacting with the page.
  • Use uBlock Origin and a reputable AV that has PowerShell script scanning.

I have seen fake CAPTCHAs before. Many of you have been hit by this. But this one is important as it includes device recovery phrases.

What if you are a wallet user? It is your time horizon. It grows

We are already [the period like] the 2025 Regulatory Sprint. Under MiCA, the consumer protection laws are tighter. But the enforcement of all these cannot catch the anonymous phishing in their command in whatever location. The next order, the policymakers will not be smart contracts. They will be targeting device security. The responsibility will start shifting from the user risk to the device buyer.

So, when you are drawn to see the market in the coming weeks, there is a new metric to check:

Follow the new blocks. Find vulnerability exploits.

The mapping is clear. The data is clear. The issue is no longer in the blockchain. It is on your device.

Act accordingly.

Agent are live. Watch the chain. But also watch clipboard.

Phrases are key. Storage is physical.

The command is active. The wipe is imminent.

Market Prices

BTC Bitcoin
$75,816.7 -2.84%
ETH Ethereum
$2,402.91 -4.46%
SOL Solana
$97.1 -5.49%
BNB BNB Chain
$715.1 -0.54%
XRP XRP Ledger
$1.29 -9.36%
DOGE Dogecoin
$0.0801 -4.38%
ADA Cardano
$0.1950 -6.47%
AVAX Avalanche
$7.26 -4.26%
DOT Polkadot
$0.9418 -6.15%
LINK Chainlink
$10.92 -5.58%

Fear & Greed

51

Neutral

Market Sentiment

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Tools

All →

Altseason Index

42

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$75,816.7
1
Ethereum
ETH
$2,402.91
1
Solana
SOL
$97.1
1
BNB Chain
BNB
$715.1
1
XRP Ledger
XRP
$1.29
1
Dogecoin
DOGE
$0.0801
1
Cardano
ADA
$0.1950
1
Avalanche
AVAX
$7.26
1
Polkadot
DOT
$0.9418
1
Chainlink
LINK
$10.92

🐋 Whale Tracker

🟢
0x8272...72cc
6h ago
In
26,416 BNB
🔴
0xa13e...7631
12m ago
Out
2,274.57 BTC
🟢
0xe3d4...fa2d
12h ago
In
4,779,003 USDC

💡 Smart Money

0xad41...3e23
Institutional Custody
+$3.6M
80%
0x813a...9014
Arbitrage Bot
-$3.2M
87%
0x9a03...6897
Arbitrage Bot
+$0.8M
86%