Fake CAPTCHA Scam Abuses Verification Clicks to Send Costly International Texts

2026-04-25T20:51:46Zfcf4a4fc1c340ce91f26d99471b2f6c3357074c57bc983f9e0d58b0d0b99fa04
313 TeamAI assistantsAnthropic vendor breachBitwarden CLIBluesky outageClick2SMSClickFixDDoSDLL sideloadingDependabot supply-chainDiscordGoGra LinuxHarvester APTHexDex arrestLOTUSLITEMustang PandaShai-HuludTeamPCPback-button hijackingcmdkeyfake CAPTCHAnative Windows abuseprompt injectionregsvr32supply chain attack

What happened

Collection of April 2026 security reports covering multiple active threats and incidents: a large Click2SMS fraud campaign abusing fake CAPTCHAs and back-button hijacking to trick victims into sending costly international texts; a ClickFix variant that leverages native Windows tools (cmdkey, regsvr32) to run commands and persist while evading detection; TeamPCP supply-chain compromise using the Bitwarden CLI and GitHub Dependabot to distribute the Shai-Hulud malware and poison developer tooling; Harvester APT deploying new GoGra Linux malware (fake PDFs, Microsoft APIs) to target South Asia; a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
fcf4a4fc1c340ce91f26d99471b2f6c3357074c57bc983f9e0d58b0d0b99fa04
Enrichment time
2026-04-25T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.