Capcha was a trap: how a fake check Cloudflare infected a computer of an industrial company

Solar 4RAYS experts dismantled the attack, where the check of captcha led to the infection of the work station of the Russian industrial company. The employee was lured to the phishing page with animated Cloudflare and persuaded to execute the command through the Win+R window. After entering, the team launched PowerShell and downloaded the executable file with galaktikabt. The computer got Santa Stealer, malware for stealing accounts, tokens, browser sessions and other sensitive information.

The incident occurred in March 2026, according to a report by Solar 4RAYS. The entry point was the site kentuckyfiredpartment,[.com), where the visitor was promised increased confidentiality and token for 90 days after the check was passed. The resource galaktikabt[.]ru, from which the file was downloaded, experts call a legitimate site, previously compromised by the attackers.

Santa Stealer is distributed according to the model of malicious service. Buyers get a builder, set up a specific campaign and choose modules for data theft. In the current version, the basic tariff increased to $ 200, the premium remained at the level of $ 300, there was also an indefinite tariff for $ 1000. Extended features allow you to search for keyword files, delay the start, combine the style with a legitimate file and replace cryptocurrency addresses in a clipboard.

The infection chain included two components: a dragon on Go and the main load on C. The driver decograph decrypted the malicious code and ran the payload right in the process memory, without saving the main file on the disk. This technique reduces the number of traces in the system and complicates the detection of signaling means of protection.



Santa Stealer is designed to quickly steal everything that can be sold or used for further attacks. The malware collects browser data, in-session cookies, Discord and Steam tokens, information from enterprise VPN clients, access to Azure and Google Cloud, crypto wallets, files and system information. In the study, the Anti-CIS check was disabled: the code can stop working on systems with signs of the CIS countries, but the campaign operator turned off the protection, since the attack was aimed at Russian users.

In the new version, Santa Stealer was able to hide communication with the command server through Cloudflare WARP and WireGuard. From the side, network traffic can resemble conventional UDP packets to the Cloudflare infrastructure, and the real address of the control server remains inside the tunnel. As a spare channel, malware addresses the controlled pages in Telegram and Mastodon, from where it extracts new C2 domains.

The researchers also linked the Santa Stealer infrastructure to reselling stolen accounts, primarily Roblox. According to Solar 4RAYS, the alleged developer of the style is associated with sellers of accounts on shadow platforms where the origin of the goods is not hidden. Such a scheme increases the risk to victims: stolen data can get not only to the buyer of malicious service, but also to the developer, intermediaries or other infrastructure participants.

Solar 4RAYS recommends companies to combine employee training with technical startup restrictions. To protect against ClickFix-attacks, experts advise to block the execution of PowerShell, VBS and executable files from temporary folders, download directories and other untrusted directories, control launches via RunMRU, use EDR or XDR with active blocking suspicious behavior, and identify attempts to raise WireGuard and VPN tunnels. After infecting one password change, it is not enough: the stylers steal active sessions, so companies need to withdraw tokens, reset the web sessions, change passwords and isolate the host.
 
Top Bottom