A campaign tied to compromised WordPress sites is being used to push deceptive CAPTCHA prompts and a mix of ransomware, credential theft, file theft, and remote monitoring claims.
A reported CERT-UA attribution points to a state-linked cluster using verification-themed deception to make victims run the first step of their own compromise.