Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain
ID: 520f5fc9-0faa-5c20-964f-286b08f0b81b
STIX ID: report--520f5fc9-0faa-5c20-964f-286b08f0b81b
Feed Name: TrendAI Security Blog
Trend Micro documents an active fake-CAPTCHA campaign that tricks users into pasting mshta/PowerShell commands (via phishing, malvertising, SEO poisoning or malicious PDFs) which execute obfuscated scripts—including JavaScript injected into MP3 files—and download multistage payloads that deploy info-stealers and RATs (Lumma Stealer, Emmenhtal, Rhadamanthys, AsyncRAT, XWorm); the report includes telemetry, IoCs, attack-chain analysis, and defensive recommendations such as disabling Run dialog, enforcing least privilege, monitoring clipboard/process behavior, and enabling memory protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
