Hackers Use Fake Cloudflare CAPTCHA and BSOD Lures to Deliver SmartRAT Malware

Cybersecurity researchers have uncovered a new malware campaign using AI-generated websites to trick users into downloading a dangerous remote access Trojan (RAT).

Discovered by Zscaler ThreatLabz in March 2026, the campaign targets customers of a major Brazilian bank using a deceptive technique known as ClickFix.

By displaying a fake Cloudflare CAPTCHA and a simulated Blue Screen of Death (BSOD), hackers pressure victims into running malicious PowerShell commands.

The resulting infection delivers SmartRAT, a highly capable banking malware designed to steal financial data and give attackers full control over a compromised system.

Trend Micro researchers previously tracked a similar attack path, dubbing the malware Banana RAT.

Fake Cloudflare Lures SmartRAT

The attack begins when a user visits a typosquatting domain, such as cartaobb[.]com, which impersonates a legitimate Brazilian bank.

Researchers noted that the fraudulent webpage contains AI-generated code comments, suggesting that threat actors are using modern website builders to scale their operations quickly.

AI generated ClickFix campaign attack chain (Source: zscaler)
AI generated ClickFix campaign attack chain (Source: zscaler)

The site greets visitors with a fake Cloudflare CAPTCHA prompt that mimics a standard security check.

To prevent researchers from analyzing the trap, the webpage uses anti-inspection scripts that turn off developer tools and repeatedly clear the browser’s console log.

Once the user clicks the fake CAPTCHA, a malicious script immediately copies a PowerShell command to the victim’s clipboard. The browser is then forced into fullscreen mode to display a fake BSOD error message.

This screen acts as a system recovery lure, explicitly instructing the trapped user to press a specific key combination and paste the copied command into the Windows Run dialog.

Fake website impersonating a Brazilian bank using a ClickFix lure (Source: zscaler)
Fake website impersonating a Brazilian bank using a ClickFix lure (Source: zscaler)

The lockdown routine restricts keyboard input while temporarily allowing only the keys needed to execute this malicious flow.

If the victim falls for the trick, the executed PowerShell command retrieves a stealth dropper script from a remote server.

This dropper quietly hides its console window, downloads an encrypted payload, and executes it without raising immediate suspicion.

The final decrypted payload is SmartRAT, a sophisticated threat built entirely in PowerShell. To ensure it survives system reboots, the malware establishes persistence by creating a scheduled task or installing a Windows service with elevated system privileges.

SmartRAT is heavily focused on financial theft and monitoring. The malware actively monitors a victim’s active windows for keywords related to popular banks, credit unions, and cryptocurrency platforms such as Binance and MercadoPago.

When a target application is detected, it immediately alerts the threat actor.

The operator can then deploy full-screen fake overlays that mimic legitimate banking interfaces, tricking users into entering their passwords and sensitive data directly into the attacker’s hands, Zscaler said.

Indicators of Compromise

IndicatorDescription
crefisa[.]onlineFraudulent domain
vfsgloball[.]netFraudulent domain
cartaobb.comFraudulent domain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories