By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners
Tech News

Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners

By Viral Trending Content 3 Min Read
Share
SHARE

Feb 13, 2025Ravie LakshmananWeb Security / Cloud Security

CAPTCHA Trick on Webflow

A widespread phishing campaign has been observed leveraging bogus PDF documents hosted on the Webflow content delivery network (CDN) with an aim to steal credit card information and commit financial fraud.

“The attacker targets victims searching for documents on search engines, resulting in access to malicious PDF that contains a CAPTCHA image embedded with a phishing link, leading them to provide sensitive information,” Netskope Threat Labs researcher Jan Michael Alcantara said.

Cybersecurity

The activity, ongoing since the second half of 2024, entails users looking for book titles, documents, and charts on search engines like Google to redirect users to PDF files hosted on Webflow CDN.

These PDF files come embedded with an image that mimics a CAPTCHA challenge, causing users who click on it to be taken to a phishing page that, this time, hosts a real Cloudflare Turnstile CAPTCHA.

In doing so, the attackers aim to lend the process a veneer of legitimacy, fooling victims into thinking that they had interacted with a security check, while also evading detection by static scanners.

Users who complete the genuine CAPTCHA challenge are subsequently redirected to a page that includes a “download” button to access the supposed document. However, when the victims attempt to complete the step, they are served a pop-up message asking them to enter their personal and credit card details.

CAPTCHA Trick on Webflow

“Upon entering credit card details, the attacker will send an error message to indicate that it was not accepted,” Michael Alcantara said. “If the victim submits their credit card details two or three more times, they will be redirected to an HTTP 500 error page.”

The development comes as SlashNext detailed a new phishing kit named Astaroth (not to be confused with a banking malware of the same name) that’s advertised on Telegram and cybercrime marketplaces for $2,000 in exchange for six-months of updates and bypass techniques.

Cybersecurity

Like phishing-as-a-service (PhaaS) offerings, it allows cyber crooks the ability to harvest credentials and two-factor authentication (2FA) codes via bogus login pages that mimic popular online services.

“Astaroth utilizes an Evilginx-style reverse proxy to intercept and manipulate traffic between victims and legitimate authentication services like Gmail, Yahoo, and Microsoft,” security researcher Daniel Kelley said. “Acting as a man-in-the-middle, it captures login credentials, tokens, and session cookies in real time, effectively bypassing 2FA.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

M5 Ultra Mac Studio Leaks: 8K Video and GPU Benchmarks

U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage

Meta and Google face multi-million dollar fines for addictive apps

Best Noise-Canceling Earbuds: Bose, Sony, Apple, and More

Plans for new Irish supercomputer CASPIR moves to next stage

TAGGED: Cloud security, Cyber Security, Cybersecurity, data breach, digital forensics, Internet, Malware, online fraud, phishing, social engineering, Threat Intelligence, web security
Share This Article
Facebook Twitter Copy Link
Previous Article OnePlus Confirms Open 2 Foldable Won’t Be Released This Year
Next Article Avowed – 15 New Details You Need to Know
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Trump says deal could be reached ‘soon’ as Iran warns against US ground invasion
World News
Bitcoin Struggles Under Key Adjusted Realized Price — Why It Matters
Crypto
Star Wars Zero Company Studio is All-In on Tactical Combat, but “Depth Doesn’t Cost You Elegance”
Gaming News
M5 Ultra Mac Studio Leaks: 8K Video and GPU Benchmarks
Tech News
4 Takeaways From the NCAA Men's Basketball Tournament Elite Eight
Sports
Oil Price Today (March 30): Oil jumps 3% to near $120 amid expectations of US ground offensive in Iran. What lies ahead?
Business
Lido DAO proposes $20M LDO buyback to reverse historic price fall
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?