One fake-CAPTCHA scam now beacons from 5,400 sites.

Victims install the malware themselves, so no software patch can stop it.

A fake CAPTCHA tricks users into pasting a hidden command into their own Run or Terminal prompt.

Even Russia’s Sandworm has adopted the technique, security researchers say.

How each outlet framed it
Ars Technica
explains pivot from code-signing to social-engineering legitimacy, covers macOS Gatekeeper bypasses and blockchain-hosted C&C

Sources: Ars Technica