We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Win32/Captiya
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
Windows Defender Antivirus detects and removes this threat.
Win32/Captiya is a trojan that tries to decode CAPTCHA. CAPTCHA is an acronym for 'Completely Automated Public Turing test to tell Computers and Humans Apart', which is usually used for creating new e-mail accounts. Decoded CAPTCHAs can be used to automatically register email accounts. The automatic mass creation of email accounts can be used for spamming or other malicious activities.
Win32/Captiya works in concert with Spammer:Win32/Newacc.A in order to automatically registers new e-mail accounts, and communicates with a Web Service in order to bypass CAPTCHA protection. Win32/Captiya communicates to remote sites in order to aid and complete the registration of new accounts.