Hackers Abuse Google CAPTCHA, WebDAV and BNB Smart Chain to Deploy Credential
A multi-stage malware operation that combines fake Google CAPTCHA prompts, WebDAV-hosted DLL execution, malicious Cloudflare Workers and BNB Smart Chain smart contracts to deploy the Amatera information stealer. The activity was first identified in April 2026 after a Ukrainian government organization executed a disguised DLL named “verification.google” from a WebDAV path using the 32-bit rundll32.exe […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
