PULSE NAME
PhantomCaptcha: Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operation
WHITE PhantomCaptcha AlienVault 2025-10-22 Modified: 2025-11-21
22
IOCs
MEDIUM VOLUME
A coordinated spearphishing campaign targeted NGOs and Ukrainian government administrations involved in war relief efforts. The attack used emails impersonating the Ukrainian President's Office with weaponized PDFs, employing a fake Cloudflare captcha page to execute malware. The final payload was a WebSocket RAT enabling remote command execution and data exfiltration. Despite six months of preparation, the attackers' infrastructure was only active for one day, indicating sophisticated planning and operational security. An additional mobile attack vector was discovered, using fake applications to collect data from Android devices. The campaign demonstrated extensive operational planning, compartmentalized infrastructure, and deliberate exposure control.
Indicators of Compromise (22)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 77f27ffccd75fc39ea003cbde32c624b 2025-10-22
FileHash-MD5 842d96f208b567e58c5656017fb67df6 2025-10-22
FileHash-SHA1 5ac660ecbbde66ba9d46f37f9ddbc904e4c5d9e8 2025-10-22
FileHash-SHA1 9d3a0c7c7859cb71902c61b7664a925781b08ebf 2025-10-22
FileHash-SHA256 07d9deaace25d90fc91b31849dfc12b2fc3ac5ca90e317cfa165fe1d3553eead 2025-10-22
FileHash-SHA256 19bcf7ca3df4e54034b57ca924c9d9d178f4b0b8c2071a350e310dd645cd2b23 2025-10-22
FileHash-SHA256 21bdf1638a2f3ec31544222b96ab80ba793e2bcbaa747dbf9332fb4b021a2bcd 2025-10-22
FileHash-SHA256 3324550964ec376e74155665765b1492ae1e3bdeb35d57f18ad9aaca64d50a44 2025-10-22
FileHash-SHA256 4bc8cf031b2e521f2b9292ffd1aefc08b9c00dab119f9ec9f65219a0fbf0f566 2025-10-22
FileHash-SHA256 55677db95eb5ddcca47394d188610029f06101ee7d1d8e63d9444c9c5cb04ae1 2025-10-22
FileHash-SHA256 5f42130139a09df50d52a03f448d92cbf40d7eae74840825f7b0e377ee5c8839 2025-10-22
FileHash-SHA256 6f9a7ab475b4c1ea871f7b16338a531703af0443f987c748fa5fff075b8c5f91 2025-10-22
FileHash-SHA256 8ef05f4d7d4d96ca6f758f2b5093b7d378e2e986667967fe36dbdaf52f338587 2025-10-22
FileHash-SHA256 b02d8f8cf57abdc92b3af2545f1e46f1813f192f4a200a3de102fd38cf048517 2025-10-22
FileHash-SHA256 bcb9e99021f88b9720a667d737a3ddd7d5b9f963ac3cae6d26e74701e406dcdc 2025-10-22
FileHash-SHA256 e8d0943042e34a37ae8d79aeb4f9a2fa07b4a37955af2b0cc0e232b79c2e72f3 2025-10-22
domain bsnowcommunications.com 2025-10-22
domain goodhillsenterprise.com 2025-10-22
domain lapas.live 2025-10-22
domain princess-mens-club.com 2025-10-22
domain princess-mens.click 2025-10-22
domain zoomconference.click 2025-10-22