logo

Lunar Spider Expands their Web via FakeCaptcha

ID: 24cdd3c9-d4d0-519c-a9f1-c4694aad7388

STIX ID: report--24cdd3c9-d4d0-519c-a9f1-c4694aad7388

Feed Name: NVISO Labs

Threat Score
75/100

Date Published: 2025-10-01

Date Updated: 2026-04-28

Author: Efstratios Lontzetidis

...
...

NVISO documents an active Lunar Spider campaign delivering the Latrodectus V2 loader by exploiting CORS-vulnerable websites and injecting a FakeCaptcha (TeleCaptcha) JavaScript that copies a PowerShell download command to victims; the installer deploys a signed Intel EXE which sideloads a malicious DLL, enabling C2 communication, enumeration, and providing access for ransomware affiliates. The blog provides detailed technical analysis, IoCs (domains and SHA-256 hashes), code snippets, and hunting/detection queries (URLScan, KQL) mapped to MITRE ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.