Executive Summary
On October 8, 2025, a sophisticated spear-phishing campaign, dubbed PhantomCaptcha, targeted Ukraine war relief organizations, including members of the International Red Cross and Norwegian Refugee Council. Attackers sent counterfeit Zoom invitations and weaponized PDF attachments designed to lure aid workers into executing a remote access trojan (RAT). Leveraging WebSockets for covert command-and-control, the threat actors gained unauthorized access, potentially jeopardizing sensitive wartime humanitarian data and operations. The campaign showcased precise targeting, the use of specially crafted lures reflecting victims’ work environments, and advanced C2 techniques to evade detection.
This incident underscores the increasing cyber threats facing humanitarian sectors amid ongoing geopolitical conflicts. As military and civilian support organizations become more digitalized and visible, spear-phishing and RAT-based compromises are on the rise, necessitating urgent security enhancements and compliance vigilance.
Why This Matters Now
The PhantomCaptcha attack illustrates the urgent need for robust security in non-profit and humanitarian sectors, which have become high-value targets in active conflict zones. With the prevalence of advanced phishing lures and covert malware delivery, organizations handling sensitive data must fortify their defenses against identity-driven and file-based threats.
Attack Path Analysis
Attackers initiated the breach via spear-phishing emails impersonating Zoom invites, delivering weaponized PDFs that installed a remote access trojan (RAT). Upon establishing initial access, the adversary leveraged the RAT to escalate privileges on compromised endpoints, likely seeking greater access in the target environment. With elevated permissions, lateral movement was attempted to other workloads using east-west communication within the cloud or hybrid infrastructure. The RAT established a command-and-control channel over WebSockets, enabling persistent communication and attacker control. Sensitive data was identified and exfiltrated via encrypted outbound traffic to attacker-controlled infrastructure. The campaign's end goal was likely espionage or operational disruption targeting Ukraine aid organizations, with minimal operational impact reported at this stage.
Kill Chain Progression
Initial Compromise
Description
Attackers crafted spear-phishing emails with fake Zoom meeting links and weaponized PDF attachments, tricking victims into running a malicious payload (RAT) within the organization.
Related CVEs
CVE-2025-40991
CVSS 5.1Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 allows remote attackers to steal session cookies via the 'description' parameter.
Affected Products:
Creativeitem Ekushey CRM – 5.0
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Command and Scripting Interpreter
Ingress Tool Transfer
Application Layer Protocol: Web Protocols
Valid Accounts
Impair Defenses: Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Training for Phishing and Social Engineering
Control ID: 5.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6(2)
CISA ZTMM 2.0 – User Cybersecurity Training
Control ID: User: Awareness and Training
NIS2 Directive – Technical and Organisational Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Non-Profit/Volunteering
Humanitarian aid organizations face spear-phishing attacks through fake Zoom meetings and weaponized PDFs, requiring enhanced egress security and threat detection capabilities.
Government Administration
Government agencies supporting Ukraine relief efforts are vulnerable to coordinated campaigns using remote access trojans with WebSocket C2 communications requiring zero trust segmentation.
International Affairs
International organizations like Red Cross face targeted attacks exploiting trust relationships, necessitating multicloud visibility and encrypted traffic protection for sensitive operations.
Health Care / Life Sciences
Healthcare organizations providing humanitarian aid require enhanced threat detection and anomaly response capabilities to protect against PhantomCaptcha-style attacks targeting relief coordination.
Sources
- Ukraine Aid Groups Targeted Through Fake Zoom Meetings and Weaponized PDF Fileshttps://thehackernews.com/2025/10/ukraine-aid-groups-targeted-through.htmlVerified
- PhantomCaptcha | Multi-Stage WebSocket RAT Targets Ukraine in Single-Day Spearphishing Operationhttps://www.sentinelone.com/labs/phantomcaptcha-multi-stage-websocket-rat-targets-ukraine-in-single-day-spearphishing-operation/Verified
- PhantomCaptcha targets Ukraine relief groups with WebSocket RAT in October 2025https://securityaffairs.com/183720/apt/phantomcaptcha-targets-ukraine-relief-groups-with-websocket-rat.htmlVerified
- PhantomCaptcha ClickFix attack targets Ukraine war relief orgshttps://www.bleepingcomputer.com/news/security/phantomcaptcha-clickfix-attack-targets-ukraine-war-relief-orgs/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Cloud Network Security Framework controls such as zero trust segmentation, east-west traffic security, egress policy enforcement, and inline threat detection would have significantly constrained attacker movement, lateral spread, C2 communication, and data exfiltration—even after initial compromise by phishing.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of anomalous inbound connections or suspicious attachment execution.
Control: Zero Trust Segmentation
Mitigation: Limit risk of privilege escalation by enforcing least privilege and workload segmentation.
Control: East-West Traffic Security
Mitigation: East-west segmentation blocks unauthorized lateral connections between workloads.
Control: Cloud Firewall (ACF)
Mitigation: Outbound C2 channels detected and potentially blocked by egress policy enforcement.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized outbound data flows to unknown or risky destinations.
Comprehensive visibility and real-time monitoring accelerate incident response and limit potential harm.
Impact at a Glance
Affected Business Functions
- Humanitarian Aid Coordination
- Government Administration
Estimated downtime: 1 days
Estimated loss: $50,000
Potential exposure of sensitive communications and operational data of humanitarian organizations and government entities.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation to restrict lateral movement and contain breaches within tightly defined workload boundaries.
- • Enforce east-west traffic controls and anomaly detection to quickly spot and block internal pivots by compromised assets.
- • Implement egress policy enforcement and outbound filtering to halt C2 connections and data exfiltration over unknown channels.
- • Leverage centralized multicloud visibility for rapid detection, incident response, and compliance monitoring across hybrid environments.
- • Integrate baseline anomaly detection for early, behavioral identification of inbound phishing and unusual user or workload activity.



