Phishing pages lure users into malware, but the URLs behind the scams keep changing. Investigators tracked four distinct attack chains that started with the same hosting network, even as domains, downloads, and command servers shifted over five months. Following the same tactics as previous fake CAPTCHA attacks, adhering to those instructions can initiate an infection without opening a suspicious attachment.
ActiveSOC reported this finding in a report shared with ZeroOwl (ZeroOwl), stating that four cases reached command execution, while most stopped at the lure page. One chain installed a stealer that survived a reboot, while another placed a Node.js implant on a host and remained active for nearly two days.
Researchers identified at least seven entry addresses across six separate network ranges, and the provider expanded its announced space during the investigation. The routes and chains that reached us (Source – ACTIVESOC) Others exploited compromised retail or restaurant sites, mirroring research on poisoned redirects where the browser's address bar displayed a legitimate website while an injected script provided the fake challenge. This investigation underscores what remains hidden behind changing names and why removing one lure at a time makes little difference.
Defenders should also monitor browsers switching to command interpreters, unsigned libraries alongside signed software, and trusted runtimes launched from user-editable folders. File path: %LOCALAPPDATA%\Temp\ Randomly named archive staging directory.




![Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Decentralized-Identity-Solutions-1.webp)






