logo

Behind the CAPTCHA: A Clever Gateway of Malware

ID: 2e8cfad3-f970-5406-b247-be3ce40f2f14

STIX ID: report--2e8cfad3-f970-5406-b247-be3ce40f2f14

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2024-09-20

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs observed a global ClickFix campaign that lures victims to fake CAPTCHA pages—delivered via cracked-game download redirects and GitHub-impersonation phishing—where malicious JavaScript/PowerShell is copied to the clipboard and tricked into execution (via Win+R/mshta), resulting in Lumma Stealer being downloaded and run; the report includes technical analysis, IoCs (URLs and SHA256 hashes), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.