We found fake CAPTCHAs hiding malware in uploaded files

3 ovaistariq 1 5/21/2025, 3:47:43 PM tigrisdata.com ↗

Comments (1)

ovaistariq · 19h ago
At Tigris, we encountered a pattern where uploaded files included fake CAPTCHA screens as a way to hide malicious payloads and bypass detection.

These fake CAPTCHAs look legitimate but are used to trick users into executing malware, and they're surprisingly effective at evading static analysis.

We shared what we found and how we're improving our detection pipeline: https://www.tigrisdata.com/blog/fake-captchas/