← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 23, 2026 · 11:53via Cyber Security News

The Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves

Brief

Fake verification pages are steering people toward malware, but the web addresses behind the lures keep changing.

Over five months, investigators tracked four different attack chains that began with the same hosting network, even as domains, downloads and command servers shifted. The pattern makes blocking individual websites a poor way to stop the first step.

Most victims reached a fake CAPTCHA through online ads, although one arrived through an emailed link. The page quietly copied a command to the clipboard, then told the visitor to open the Windows Run box and paste it.

As with earlier fake CAPTCHA attacks , following those instructions could start an infection without opening a suspicious attachment.

Analysts from ActiveSOC identified the shared infrastructure while reviewing roughly 150 alerts across monitored environments.

Read more on Cyber Security News