Security bulletin with exclamation point symbol in the middle of the screen
Security bulletin with exclamation point symbol in the middle of the screen

Healthcare Sector Targeted by Fake CAPTCHA Attack on HEP2go to Deliver Infostealer Malware

Security bulletin with exclamation point symbol in the middle of the screen
6 min read

Arctic Wolf has recently observed a campaign targeting the healthcare sector, where victims visiting the widely used physical therapy video site HEP2go are redirected to a fake CAPTCHA webpage when they attempt to visit multiple parts of the website. This CAPTCHA provides instructions that trigger PowerShell code execution and the eventual loading of infostealer malware. 

Fake CAPTCHA screen

HEP2go is an online platform that allows physical therapists, trainers, and healthcare professionals to create and share Home Exercise Programs (HEPs) with their clients. In late February, several users on public forums began reporting that the HEP2go website was compromised. At this time, Arctic Wolf is not aware of when the HEP2go website will be fixed and strongly recommends avoiding it until the issue is resolved. 

Arctic Wolf currently has detections in place that identify malicious PowerShell substrings observed in this campaign, and we will continue to notify customers when we identify new instances of this activity through current agent and Sysmon detections. 

Recommendations 

Avoid HEP2go Indefinitely

At this time, Arctic Wolf strongly recommends avoiding HEP2go, as the website is currently compromised and not safe to visit. 

Install Arctic Wolf Agent & Sysmon

  • Arctic Wolf has implemented MDR detections for post-compromise threat activity associated with this campaign on endpoint devices. 
  • Arctic Wolf Agent and Sysmon give Arctic Wolf visibility into network and endpoint events needed to identify Tools, Techniques, and Tactics involved in this campaign. 

Note: Arctic Wolf recommends following change management best practices for deploying Agent and Sysmon, including testing changes in a testing environment before deploying to production. 

Implement Comprehensive Security Awareness Training

Arctic Wolf strongly recommends implementing comprehensive security awareness training campaigns. These initiatives are designed to equip users with the skills needed to quickly identify and report suspicious activities. 

Resources

Understand the threat landscape, and how to better defend your organization, with the 2025 Arctic Wolf Threat Report

See how Arctic Wolf utilizes threat intelligence to harden your attack surface and stop threats earlier and faster

Share this post: