{"id":28287,"date":"2020-06-19T11:30:00","date_gmt":"2020-06-19T11:30:00","guid":{"rendered":"https:\/\/icrowdnewswire.com\/?p=2607007"},"modified":"2020-06-19T11:30:00","modified_gmt":"2020-06-19T11:30:00","slug":"to-evade-detection-hackers-are-requiring-targets-to-complete-captchas","status":"publish","type":"post","link":"https:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/","title":{"rendered":"To evade detection, hackers are requiring targets to complete CAPTCHAs"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"233\" height=\"24\" src=\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"display: block; margin-bottom: 5px; clear:both;max-width: 100%;\" link_thumbnail=\"\" \/><\/p>\n<h2>Requiring human interaction thwarts automated analysis used by good guys.<\/h2>\n<section class=\"post-meta\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2020\/06\/attack-captcha-800x643.png\" alt=\"To evade detection, hackers are requiring targets to complete CAPTCHAs\" width=\"640\" height=\"514\" \/><\/section>\n<section class=\"post-meta\">\n<p>CAPTCHAs, those puzzles with muffled sounds or blurred or squiggly letters that websites use to filter out bots (<a href=\"https:\/\/arstechnica.com\/information-technology\/2012\/05\/google-recaptcha-brought-to-its-knees\/\">often<\/a>&nbsp;<a href=\"https:\/\/www.theregister.co.uk\/2009\/12\/14\/google_recaptcha_busted\/\">unsuccessfully<\/a>), have been annoying end users for more than a decade. Now, the challenge-and-response tests are likely to vex targets in malware attacks.<\/p>\n<p>Microsoft recently spotted an attack group distributing a malicious Excel document on a site requiring users to complete a CAPTCHA, most likely in an attempt to thwart automated detection by good guys. The Excel file contains macros that, when enabled, install GraceWire, a trojan that steals sensitive information such as passwords. The attacks are the work of a group Microsoft calls Chimborazo, which company researchers have been tracking since at least January.<\/p>\n<p>Previously, Microsoft observed Chimborazo distributing the Excel file in attachments included in phishing messages and later spreading through embedded Web links. In recent weeks, the group has begun sending phishing emails that change things up again. In some cases, the phishes include links that lead to redirector sites (usually legitimate sites that have been compromised). In other cases, the emails have an HTML attachment that contains a malicious&nbsp;<a href=\"https:\/\/www.w3schools.com\/tags\/tag_iframe.asp\">iframe tag<\/a>.<\/p>\n<p>Either way, clicking on the link or attachment leads to a site where targets download the malicious file, but only after completing the CAPTCHA (which is short for completely automated public Turing test to tell computers and humans apart). The purpose: to thwart automated analysis defenders use to detect and block attacks and get attack campaigns shut down. Typically the analysis is performed by what are essentially bots that download malware samples and run and analyze them in virtual machines.<\/p>\n<p>Requiring the successful completion of a CAPTCHA means analysis will only happen when a live human being downloads the sample. Without the automation, the chances of the malicious file flying under the radar are much better. Microsoft has dubbed Chimborazo&rsquo;s ongoing attack campaign Dudear.<\/p>\n<p>&ldquo;CHIMBORAZO, the group behind Dudear campaigns that deploy the info-stealing Trojan GraceWire, evolved their methods once again in constant pursuit of detection evasion,&rdquo; Microsoft&rsquo;s Security Intelligence group wrote in a&nbsp;<a href=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1273359829390655488\">Tweet on Wednesday<\/a>. &ldquo;The group is now using websites with CAPTCHA to avoid automated analysis.&rdquo;<\/p>\n<div class=\"SandboxRoot env-bp-350\" data-twitter-event-id=\"0\">\n<div id=\"twitter-widget-0\" class=\"EmbeddedTweet EmbeddedTweet--cta js-clickToOpenTarget\" lang=\"en\" data-click-to-open-target=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1273359829390655488\" data-iframe-title=\"Twitter Tweet\" data-scribe=\"page:tweet\" data-twitter-event-id=\"1\">\n<div class=\"EmbeddedTweet-tweetContainer\">\n<div class=\"EmbeddedTweet-tweet\">\n<blockquote class=\"Tweet h-entry js-tweetIdInfo subject expanded\" cite=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1273359829390655488\" data-tweet-id=\"1273359829390655488\" data-scribe=\"section:subject\">\n<div class=\"Tweet-header\"><a class=\"TweetAuthor-avatar  Identity-avatar u-linkBlend\" href=\"https:\/\/twitter.com\/MsftSecIntel\" data-scribe=\"element:user_link\" aria-label=\"Microsoft Security Intelligence (screen name: MsftSecIntel)\"><img decoding=\"async\" class=\"Avatar\" src=\"https:\/\/pbs.twimg.com\/profile_images\/1268200269277351936\/a2naHzbe_normal.png\" alt=\"\" data-scribe=\"element:avatar\" data-src-2x=\"https:\/\/pbs.twimg.com\/profile_images\/1268200269277351936\/a2naHzbe_bigger.png\" data-src-1x=\"https:\/\/pbs.twimg.com\/profile_images\/1268200269277351936\/a2naHzbe_normal.png\" \/><\/a><\/p>\n<div class=\"TweetAuthor js-inViewportScribingTarget\" data-scribe=\"component:author\">\n<div class=\"TweetAuthor-nameScreenNameContainer\"><span class=\"TweetAuthor-decoratedName\"><span class=\"TweetAuthor-name Identity-name customisable-highlight\" title=\"Microsoft Security Intelligence\" data-scribe=\"element:name\">Microsoft Security Intelligence<\/span><\/span><\/p>\n<div class=\"Icon Icon--verified \" title=\"Verified Account\" role=\"img\" aria-label=\"Verified Account\">&nbsp;<\/div>\n<p><span class=\"TweetAuthor-decoratedName\"><span class=\"TweetAuthor-verifiedBadge\" data-scribe=\"element:verified_badge\"><strong class=\"u-hiddenVisually\"><img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11.2.0\/72x72\/2714.png\" alt=\"\u2714\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\" \/><\/strong><\/span><\/span><span class=\"TweetAuthor-screenName Identity-screenName\" dir=\"ltr\" title=\"@MsftSecIntel\" data-scribe=\"element:screen_name\">@MsftSecIntel<\/span><\/div>\n<\/div>\n<div class=\"Tweet-brand\">\n<div class=\"Icon Icon--twitter \" title=\"View on Twitter\" role=\"presentation\" aria-label=\"View on Twitter\">&nbsp;<\/div>\n<\/div>\n<\/div>\n<div class=\"Tweet-body e-entry-content\" data-scribe=\"component:tweet\">\n<div class=\"Tweet-target js-inViewportScribingTarget\">&nbsp;<\/div>\n<p class=\"Tweet-text e-entry-title\" dir=\"ltr\" lang=\"en\">CHIMBORAZO, the group behind Dudear campaigns that deploy the info-stealing Trojan GraceWire, evolved their methods once again in constant pursuit of detection evasion. The group is now using websites with CAPTCHA to avoid automated analysis.<\/p>\n<div class=\"Tweet-card\">\n<article class=\"MediaCard\n           \n           customisable-border\" dir=\"ltr\" data-scribe=\"component:card\"><\/p>\n<div class=\"MediaCard-media\" data-scribe=\"element:photo\">\n<div class=\"MediaCard-widthConstraint js-cspForcedStyle\" data-style=\"max-width: 1200px\">\n<div class=\"MediaCard-mediaContainer js-cspForcedStyle MediaCard--roundedTop MediaCard--roundedBottom\" data-style=\"padding-bottom: 80.3333%\"><a class=\"MediaCard-mediaAsset NaturalImage\" href=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1273359829390655488\/photo\/1\"><img loading=\"lazy\" decoding=\"async\" class=\"NaturalImage-image\" title=\"View image on Twitter\" src=\"https:\/\/pbs.twimg.com\/media\/Eavh0gxUwAAnctL?format=png&amp;name=small\" alt=\"View image on Twitter\" width=\"449\" height=\"360\" data-image=\"https:\/\/pbs.twimg.com\/media\/Eavh0gxUwAAnctL\" data-image-format=\"png\" \/><\/a><\/div>\n<\/div>\n<\/div>\n<\/article>\n<\/div>\n<div class=\"TweetInfo\">\n<div class=\"TweetInfo-like\">\n<div data-scribe=\"element:heart\">\n<div class=\"Icon Icon--heart \" title=\"Like\" role=\"img\" aria-label=\"Like\">&nbsp;<\/div>\n<\/div>\n<p><a class=\"TweetInfo-heart\" title=\"Like\" href=\"https:\/\/twitter.com\/intent\/like?tweet_id=1273359829390655488\" data-scribe=\"component:actions\"><span class=\"TweetInfo-heartStat\" data-scribe=\"element:heart_count\">150<\/span><\/a><\/div>\n<div class=\"TweetInfo-timeGeo\"><a class=\"u-linkBlend u-url customisable-highlight long-permalink\" href=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1273359829390655488\" data-datetime=\"2020-06-17T21:00:15+0000\" data-scribe=\"element:full_timestamp\"><time class=\"dt-updated\" title=\"Time posted: June 17, 2020 21:00:15 (UTC)\" datetime=\"2020-06-17T21:00:15+0000\">2:00 AM &#8211; Jun 18, 2020<\/time><\/a><\/div>\n<div class=\"tweet-InformationCircle\" data-scribe=\"element:notice\"><a class=\"Icon Icon--informationCircleWhite js-inViewportScribingTarget\" title=\"Twitter Ads info and privacy\" href=\"https:\/\/support.twitter.com\/articles\/20175256\"><span class=\"u-hiddenVisually\">Twitter Ads info and privacy<\/span><\/a><\/div>\n<\/div>\n<\/div>\n<\/blockquote>\n<\/div>\n<div class=\"CallToAction-icon\" data-scribe=\"element:conversation_icon\">\n<div class=\"Icon Icon--replyCTA \" title=\"View conversation on Twitter\" role=\"img\" aria-label=\"View conversation on Twitter\">&nbsp;<\/div>\n<\/div>\n<div class=\"CallToAction-text\" data-scribe=\"element:conversation_text\">85 people are talking about this<\/div>\n<div class=\"CallToAction-chevron\" data-scribe=\"element:cta_chevron\">\n<div class=\"Icon Icon--chevronRightCTA \" title=\"View on Twitter\" role=\"img\" aria-label=\"View on Twitter\">&nbsp;<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"resize-sensor\">\n<div class=\"resize-sensor-expand\">\n<div>&nbsp;<\/div>\n<\/div>\n<div class=\"resize-sensor-shrink\">\n<div>&nbsp;<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>The attack flow looks like this:<\/p>\n<figure class=\"image shortcode-img center large\"><a class=\"enlarge\" href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2020\/06\/chimborazo-attack-chain.jpeg\" data-height=\"597\" data-width=\"1194\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2020\/06\/chimborazo-attack-chain-640x320.jpeg\" srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2020\/06\/chimborazo-attack-chain.jpeg 2x\" width=\"640\" height=\"320\" \/><\/a><figcaption class=\"caption\">\n<div class=\"caption-text\"><a class=\"enlarge-link\" href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2020\/06\/chimborazo-attack-chain.jpeg\" data-height=\"597\" data-width=\"1194\">Enlarge<\/a><\/div>\n<div class=\"caption-credit\">Microsoft Security Intelligence<\/div>\n<\/figcaption><\/figure>\n<p>In a campaign the Security Intelligence group&nbsp;<a href=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1222995250911703041\">covered in January<\/a>, Chimborazo used an IP traceback service to track the IP addresses of machines that download the malicious Excel file, presumably to also evade automated detection. Back then, it was the first time Microsoft had seen Chimborazo use redirector sites.<\/p>\n<p>J&eacute;r&ocirc;me Segura, head of threat intelligence at security provider Malwarebytes, said using CAPTCHAs in malware attacks is rare but not unprecedented. He pointed to&nbsp;<a href=\"https:\/\/twitter.com\/Secu0133\/status\/1208884240248721408\">this tweet<\/a>&nbsp;from late December that was doing the same thing. In that case attackers required targets to complete a CAPTCHA that was a knock off of Google&rsquo;s reCAPTCHA service. While fake, it served the same purpose as a real one&mdash;to thwart automated analysis by requiring a real person to download the file.<\/p>\n<p>The CAPTCHA spotted by Microsoft may also be a fake&nbsp;reCAPTCHA. The evidence: as seen in the image at the top of this post, it says reCAPTCHA and below that claims to provide &#8220;DDoS protection by Cloudflare.&#8221; Those are two separate services. (Then again, as one commenter points out, it&#8217;s possible the attackers used both services separately.) Google representatives didn&rsquo;t immediately respond to an email seeking comment for this post.<\/p>\n<p>Periodically changing up attack routines is one way attackers stay ahead of defenders, creating a never-ending back-and-forth process that requires constant vigilance for defenders to stay on top of. It&rsquo;s likely the attack group will change course again in the coming months.<\/p>\n<p><em>Post updated to add comments in the second-to-last paragraph.<\/em><\/p>\n<\/section>\n<p class=\"tags\">\n<div><strong>See Campaign: <\/strong><a href=\"https:\/\/www.theregister.co.uk\/2009\/12\/14\/google_recaptcha_busted\/\" target=\"_blank\">https:\/\/www.theregister.co.uk\/2009\/12\/14\/google_recaptcha_busted\/<\/a><br \/><b>Contact Information:<\/b><br \/>DAN GOODIN <\/p>\n<p><b>Tags:<\/b><br \/><a href=\"\"><\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/news-category\/wire\/\" rel=\"category tag\">Wire<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/global-regions\/united-states\/\" rel=\"category tag\">United States<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/language\/english\/\" rel=\"category tag\">English<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"\" alt=\"image\" width=\"400\" height=\"300\" class=\"cwdfimg\" \/><\/div>\n<div>\n<h3>Contact Information:<\/h3>\n<p>DAN GOODIN <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"233\" height=\"24\" src=\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png\" alt=\"\">Requiring human interaction thwarts automated analysis used by good guys. CAPTCHAs, those puzzles with muffled sounds or blurred or squiggly letters that websites use to filter out bots (often&nbsp;unsuccessfully), have been annoying end users for more than a decade. Now, the challenge-and-response tests are likely to vex targets in malware attacks. Microsoft recently spotted an &hellip; <a href=\"https:\/\/icrowdnewswire.com\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/\">Continue reading <span>To evade detection, hackers are requiring targets to complete CAPTCHAs<\/span><\/a> <a href=\"https:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/\" class=\"more-link\">Continue Reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":47,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,22,54],"tags":[],"class_list":["post-28287","post","type-post","status-publish","format-standard","hentry","category-english","category-united-states","category-wire"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>To evade detection, hackers are requiring targets to complete CAPTCHAs - Business<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"To evade detection, hackers are requiring targets to complete CAPTCHAs - Business\" \/>\n<meta property=\"og:description\" content=\"Requiring human interaction thwarts automated analysis used by good guys. CAPTCHAs, those puzzles with muffled sounds or blurred or squiggly letters that websites use to filter out bots (often&nbsp;unsuccessfully), have been annoying end users for more than a decade. Now, the challenge-and-response tests are likely to vex targets in malware attacks. Microsoft recently spotted an &hellip; Continue reading To evade detection, hackers are requiring targets to complete CAPTCHAs Continue Reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/\" \/>\n<meta property=\"og:site_name\" content=\"Business\" \/>\n<meta property=\"article:published_time\" content=\"2020-06-19T11:30:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png\" \/>\n<meta name=\"author\" content=\"Bilal\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Bilal\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/\",\"url\":\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/\",\"name\":\"To evade detection, hackers are requiring targets to complete CAPTCHAs - Business\",\"isPartOf\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#primaryimage\"},\"image\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png\",\"datePublished\":\"2020-06-19T11:30:00+00:00\",\"author\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/70b05bacee6cf8a877350412fae25e20\"},\"breadcrumb\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#primaryimage\",\"url\":\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png\",\"contentUrl\":\"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/ipsnews.net\/business\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"To evade detection, hackers are requiring targets to complete CAPTCHAs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ipsnews.net\/business\/#website\",\"url\":\"https:\/\/ipsnews.net\/business\/\",\"name\":\"Business\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ipsnews.net\/business\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/70b05bacee6cf8a877350412fae25e20\",\"name\":\"Bilal\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/01d05f3f41cc0f9ca88d2011a983bb3f2e83e3e92e3532188bf201df38d2aea8?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/01d05f3f41cc0f9ca88d2011a983bb3f2e83e3e92e3532188bf201df38d2aea8?s=96&d=mm&r=g\",\"caption\":\"Bilal\"},\"sameAs\":[\"https:\/\/icrowdnewswire.com\/fc\"],\"url\":\"https:\/\/ipsnews.net\/business\/author\/bilal\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"To evade detection, hackers are requiring targets to complete CAPTCHAs - Business","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/","og_locale":"en_US","og_type":"article","og_title":"To evade detection, hackers are requiring targets to complete CAPTCHAs - Business","og_description":"Requiring human interaction thwarts automated analysis used by good guys. CAPTCHAs, those puzzles with muffled sounds or blurred or squiggly letters that websites use to filter out bots (often&nbsp;unsuccessfully), have been annoying end users for more than a decade. Now, the challenge-and-response tests are likely to vex targets in malware attacks. Microsoft recently spotted an &hellip; Continue reading To evade detection, hackers are requiring targets to complete CAPTCHAs Continue Reading &rarr;","og_url":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/","og_site_name":"Business","article_published_time":"2020-06-19T11:30:00+00:00","og_image":[{"url":"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png","type":"","width":"","height":""}],"author":"Bilal","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Bilal","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/","url":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/","name":"To evade detection, hackers are requiring targets to complete CAPTCHAs - Business","isPartOf":{"@id":"https:\/\/ipsnews.net\/business\/#website"},"primaryImageOfPage":{"@id":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#primaryimage"},"image":{"@id":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#primaryimage"},"thumbnailUrl":"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png","datePublished":"2020-06-19T11:30:00+00:00","author":{"@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/70b05bacee6cf8a877350412fae25e20"},"breadcrumb":{"@id":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#primaryimage","url":"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png","contentUrl":"https:\/\/icrowdnewswire.com\/wp-content\/uploads\/2020\/06\/4001-logo-741.png"},{"@type":"BreadcrumbList","@id":"http:\/\/ipsnews.net\/business\/2020\/06\/19\/to-evade-detection-hackers-are-requiring-targets-to-complete-captchas\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ipsnews.net\/business\/"},{"@type":"ListItem","position":2,"name":"To evade detection, hackers are requiring targets to complete CAPTCHAs"}]},{"@type":"WebSite","@id":"https:\/\/ipsnews.net\/business\/#website","url":"https:\/\/ipsnews.net\/business\/","name":"Business","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ipsnews.net\/business\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/70b05bacee6cf8a877350412fae25e20","name":"Bilal","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/01d05f3f41cc0f9ca88d2011a983bb3f2e83e3e92e3532188bf201df38d2aea8?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/01d05f3f41cc0f9ca88d2011a983bb3f2e83e3e92e3532188bf201df38d2aea8?s=96&d=mm&r=g","caption":"Bilal"},"sameAs":["https:\/\/icrowdnewswire.com\/fc"],"url":"https:\/\/ipsnews.net\/business\/author\/bilal\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/28287","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/comments?post=28287"}],"version-history":[{"count":1,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/28287\/revisions"}],"predecessor-version":[{"id":28288,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/28287\/revisions\/28288"}],"wp:attachment":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/media?parent=28287"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/categories?post=28287"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/tags?post=28287"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}