Behind the CAPTCHA: A Clever Gateway of Malware
ID: 2e8cfad3-f970-5406-b247-be3ce40f2f14
STIX ID: report--2e8cfad3-f970-5406-b247-be3ce40f2f14
Feed Name: McAfee Labs Blog
Threat Score
McAfee Labs observed a global ClickFix campaign that lures victims to fake CAPTCHA pages—delivered via cracked-game download redirects and GitHub-impersonation phishing—where malicious JavaScript/PowerShell is copied to the clipboard and tricked into execution (via Win+R/mshta), resulting in Lumma Stealer being downloaded and run; the report includes technical analysis, IoCs (URLs and SHA256 hashes), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
