logo

Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain

ID: 520f5fc9-0faa-5c20-964f-286b08f0b81b

STIX ID: report--520f5fc9-0faa-5c20-964f-286b08f0b81b

Feed Name: TrendAI Security Blog

Threat Score
75/100

Date Published: 2026-01-01

Date Updated: 2026-08-21

...
...

Trend Micro documents an active fake-CAPTCHA campaign that tricks users into pasting mshta/PowerShell commands (via phishing, malvertising, SEO poisoning or malicious PDFs) which execute obfuscated scripts—including JavaScript injected into MP3 files—and download multistage payloads that deploy info-stealers and RATs (Lumma Stealer, Emmenhtal, Rhadamanthys, AsyncRAT, XWorm); the report includes telemetry, IoCs, attack-chain analysis, and defensive recommendations such as disabling Run dialog, enforcing least privilege, monitoring clipboard/process behavior, and enabling memory protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.