Cybersecurity experts have revealed the specifics of a coordinated spear-phishing campaign called PhantomCaptcha that aims to distribute a remote access trojan that leverages a WebSocket for command-and-control (C2) to organizations involved in Ukraine’s war relief efforts.
According to a new report released today by SentinelOne, the October 8, 2025, activity targeted individual members of the Norwegian Refugee Council, the United Nations Children’s Fund (UNICEF) Ukraine office, the International Red Cross, the Council of Europe’s Register of Damage for Ukraine, and Ukrainian regional government administrations in the Donetsk, Dnipropetrovsk, Poltava, and Mikolaevsk regions.
It has been discovered that the phishing emails pose as the Ukrainian President’s Office. They contain a booby-trapped PDF document with an embedded link that, when clicked, takes victims to a phony Zoom website (“zoomconference[.]app”) and deceives them into executing a malicious PowerShell command read more about Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF Files.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
