APTMembers
APT

Fake reCAPTCHA Lure Tied to Dedicated Host via Certificate Match

A phishing domain mimicking Google's reCAPTCHA challenge, verifyrecapcha.info, is flagged by 19 of 91 security engines and routes through a scripted PHP backend rather than any real verification flow. An exact TLS certificate-serial match links it directly to a single dedicated IP in Germany, exposing the infrastructure behind Cloudflare's cosmetic fronting.

Aug 3, 2026, 13:34 (UTC+9)Last seenAug 3, 2026Severity100ByCTX TeamActorTortillaIOC7MITRE10

A domain calling itself verifyrecapcha.info is not, in fact, a CAPTCHA. It is a phishing front end that mimics the verification interstitial Google uses to separate humans from bots, and it has been flagged by 19 of 91 security engines — a detection band that puts it firmly in known-bad territory even before the infrastructure underneath it is examined.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence