A sophisticated spearphishing campaign, identified as PhantomCaptcha, targeted key organizations involved in Ukraine's war relief efforts, including the International Committee of the Red Cross (ICRC), UNICEF, the Norwegian Refugee Council, and various Ukrainian regional government administrations. The attackers impersonated the Ukrainian President’s Office, sending emails with weaponized PDF attachments designed to lure recipients into clicking malicious links. These links led to a fake Cloudflare captcha page, which was actually a 'ClickFix'-style decoy, ultimately delivering a multi-stage WebSocket-based remote access trojan (RAT). The infrastructure supporting this campaign was hosted on Russian-owned servers and was only active for a single day, indicating a high level of operational security and planning, with evidence suggesting at least six months of preparation. The campaign’s technical sophistication included the use of a convincing eight-page document and a redirection to a domain masquerading as a legitimate Zoom website, further enhancing the credibility of the phishing attempt. Once the RAT was deployed, it enabled the attackers to execute arbitrary remote commands, exfiltrate sensitive data, and potentially deploy additional malware on compromised systems. Investigators also discovered a mobile attack vector, with fake Android applications designed to harvest geolocation data, contacts, media files, and other sensitive information from targeted devices. The selection of targets suggests the attackers were seeking intelligence on humanitarian operations, reconstruction planning, and international coordination related to Ukraine. Ukrainian government administrations in the Donetsk, Dnipropetrovsk, Poltava, and Mikolaevsk regions were specifically named among the targets. The campaign’s rapid disappearance after a single day of activity points to a deliberate effort to avoid detection and forensic analysis. SentinelLabs, in collaboration with the Digital Security Lab of Ukraine, led the investigation and public disclosure of the campaign. The use of Russian infrastructure and the focus on Ukrainian and international relief organizations suggest a possible geopolitical motivation, though attribution remains unconfirmed. The attack chain was designed to bypass traditional security controls by exploiting trust in official communications and leveraging multi-stage payload delivery. The campaign highlights the ongoing threat to humanitarian and governmental organizations operating in conflict zones, particularly those involved in Ukraine. Security researchers emphasize the need for heightened vigilance and advanced detection capabilities to counter such highly targeted and transient threats. The incident underscores the importance of cross-organizational intelligence sharing and rapid response to emerging spearphishing campaigns. Organizations are advised to review their email security protocols, educate staff on phishing risks, and monitor for indicators of compromise associated with the PhantomCaptcha infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On October 22, 2025, SentinelLABS and the Digital Security Lab of Ukraine publicly reported the PhantomCaptcha campaign and its technical details. The report noted overlaps with activity previously attributed to COLDRIVER but said attribution remained under investigation.
Infrastructure pivots uncovered a likely related but separately tracked Android malware operation using fake apps, including lures such as 'Princess Men’s Club.' The Android malware was designed to steal extensive device and personal data such as contacts, media, and location information.
Investigators observed the domain zoomconference[.]click being registered the day after the main lure infrastructure was used. The registration suggested the operators were maintaining or refreshing campaign infrastructure after the initial activity window.
Researchers found the user-facing lure infrastructure was active for only about a day, indicating deliberate exposure control and moderate operational security by the attackers. Backend command-and-control infrastructure remained active after the public-facing lures disappeared.
The intrusion delivered a three-stage PowerShell toolset culminating in an in-memory WebSocket-based RAT capable of arbitrary command execution and data exfiltration. Researchers said the infrastructure was largely hosted on Russian-owned or Russia-linked services.
The phishing PDFs redirected targets to a Zoom lookalike domain and then to a fake Cloudflare CAPTCHA page using a ClickFix/Paste-and-Run technique. Victims were tricked into executing a malicious PowerShell command that initiated a multi-stage infection chain.
On October 8, 2025, attackers launched a coordinated spearphishing campaign against NGOs and Ukrainian regional administrations involved in war relief, including organizations such as the Red Cross, UNICEF, and NRC. The emails impersonated the Ukrainian President’s Office and used weaponized PDFs to lure victims.
Researchers assessed the operators spent about six months preparing infrastructure for the PhantomCaptcha operation before launching the campaign. This preparation phase preceded the active spearphishing activity seen in October 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcehackread.com
Open sourcesentinelone.com
Open sourcetherecord.media
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.