logo

Fake CAPTCHA Attacks Exploit Key Entry Point for LummaStealer Malware

ID: 3a4e42a2-34ba-5126-b1a0-967b041fe8b4

STIX ID: report--3a4e42a2-34ba-5126-b1a0-967b041fe8b4

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report describes a renewed, large-scale LummaStealer campaign that leverages fake CAPTCHA 'ClickFix' social-engineering lures and CastleLoader memory-execution loaders to deliver an information-stealing payload that harvests browser credentials, cookies, 2FA tokens, crypto wallets, and other sensitive files; telemetry shows widespread activity after a prior takedown and provides detection signals (randomized DNS lookup patterns) and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.