“DeceptionAds” — Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising
ID: 5b383fcc-6ef3-5a53-8e75-cbeaade16069
STIX ID: report--5b383fcc-6ef3-5a53-8e75-cbeaade16069
Feed Name: infostealers.com
Guardio Labs documents a large-scale malvertising campaign in which attackers used Monetag (a PropellerAds subsidiary) and BeMob cloaking to distribute fake captcha pages that coerce users into executing obfuscated PowerShell commands to install the Lumma info-stealer. The campaign delivered roughly 1M ad impressions per day across 3,000+ publisher sites, leveraged cloud/CDN hosting for payload pages, and included detailed IOCs (malicious pages, BeMob URLs, and publisher domains) and a timeline of disclosure and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
