Image depicting a failed authentication screen


Fake CAPTCHA Scam Spreads Malware via Social Engineering

A new campaign uses fake CAPTCHA verification pages to trick Windows users into executing PowerShell commands that install the StealC information‑stealer malware. These pages mimic legitimate site checks (e.g., Cloudflare), creating trust that leads to malicious actions. This kind of social engineering bypasses technical defenses by exploiting user trust and routine behavior. [1] Organizations can simulate similar verification-themed lures using the PhishingBox Phishing Simulator to condition employees to question unexpected prompts before interacting.

Starkiller: Dynamic Phishing Kit Bypasses MFA

Security researchers uncovered “Starkiller,” a new phishing framework that loads real login pages inside a proxy, harvesting credentials in real time and evading multi‑factor authentication defenses. Its SaaS‑like interface makes it easy for attackers to launch convincing credential theft campaigns. [2]

Phishing Targets AI Summit Attendees via WhatsApp

Image depicting the app Whatsapp


Attendees of the India AI Impact Summit were warned of phishing scams on WhatsApp soliciting financial and sensitive details. These attacks prey on post‑event communication trust, leveraging the assumption that follow‑up messages from event organizers or peers are legitimate. [3] Event-based templates available within the PhishingBox Template Library allow security teams to recreate timely, context-driven scenarios like these in a controlled setting.

AI & Deepfake Threat Landscape Continues to Grow

Broader industry reporting indicates AI and deepfake tactics are fueling more advanced fraud, including voice and video impersonation in phishing and investment scams. These techniques blur the line between legitimate and fake content, and are likely to escalate in 2026. [4]

As AI-driven deception evolves, organizations need ongoing visibility into how employees respond to real-world phishing tactics — an approach supported by PhishingBox’s Human Risk Management platform.

[1] Windows Central – Windows PC targeted by hackers in a fake CAPTCHA scam

[2] ITPro – Starkiller: Cyber experts issue warning over new phishing kit that proxies real login pages

[3] The Times of India – IndiaAI Mission has scam warning for those who attended India AI Impact Summit 2026

[4] Accio – Phishing Scams: AI-Enhanced Threats Targeting Digital Commerce in 2026