By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners
Computing

Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners

News Room
Last updated: 2025/02/13 at 10:54 AM
News Room Published 13 February 2025
Share
SHARE

Feb 13, 2025Ravie LakshmananWeb Security / Cloud Security

A widespread phishing campaign has been observed leveraging bogus PDF documents hosted on the Webflow content delivery network (CDN) with an aim to steal credit card information and commit financial fraud.

“The attacker targets victims searching for documents on search engines, resulting in access to malicious PDF that contains a CAPTCHA image embedded with a phishing link, leading them to provide sensitive information,” Netskope Threat Labs researcher Jan Michael Alcantara said.

Cybersecurity

The activity, ongoing since the second half of 2024, entails users looking for book titles, documents, and charts on search engines like Google to redirect users to PDF files hosted on Webflow CDN.

These PDF files come embedded with an image that mimics a CAPTCHA challenge, causing users who click on it to be taken to a phishing page that, this time, hosts a real Cloudflare Turnstile CAPTCHA.

In doing so, the attackers aim to lend the process a veneer of legitimacy, fooling victims into thinking that they had interacted with a security check, while also evading detection by static scanners.

Users who complete the genuine CAPTCHA challenge are subsequently redirected to a page that includes a “download” button to access the supposed document. However, when the victims attempt to complete the step, they are served a pop-up message asking them to enter their personal and credit card details.

CAPTCHA Trick on Webflow

“Upon entering credit card details, the attacker will send an error message to indicate that it was not accepted,” Michael Alcantara said. “If the victim submits their credit card details two or three more times, they will be redirected to an HTTP 500 error page.”

The development comes as SlashNext detailed a new phishing kit named Astaroth (not to be confused with a banking malware of the same name) that’s advertised on Telegram and cybercrime marketplaces for $2,000 in exchange for six-months of updates and bypass techniques.

Cybersecurity

Like phishing-as-a-service (PhaaS) offerings, it allows cyber crooks the ability to harvest credentials and two-factor authentication (2FA) codes via bogus login pages that mimic popular online services.

“Astaroth utilizes an Evilginx-style reverse proxy to intercept and manipulate traffic between victims and legitimate authentication services like Gmail, Yahoo, and Microsoft,” security researcher Daniel Kelley said. “Acting as a man-in-the-middle, it captures login credentials, tokens, and session cookies in real time, effectively bypassing 2FA.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article All the Settings You Should Change on Your New Samsung Phone
Next Article Dell XPS 13 review: out with a whimper
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

This £19 app turns your iPhone into a scanner, and it lasts for life
News
Apple might announce the first new iOS 19 features next week
News
An “epic” comeback is in the making as Fortnite is returning to the App Store
News
Donald Trump ‘looking at’ suspending legal right to challenge one’s detention
News

You Might also Like

Computing

GNOME Showtime Accepted As Video Player App For GNOME 49

0 Min Read
Computing

The HackerNoon Newsletter: If Youre an Amazon Ring Owner, You May Be an Accidental Spy (5/9/2025) | HackerNoon

2 Min Read

New Purpose-Built Blockchain T-Rex Raises $17 Million to Transform Attention Layer In Web3 | HackerNoon

8 Min Read
Computing

Ninja Deep Research: The AI Agent Everyone Can Actually Start Using Now | HackerNoon

10 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?