logo

260 Domains Hosting 5,000 Malicious PDFs to Steal Credit Card Data

ID: dcb44f54-d032-5fa7-a03f-2f5c4c83ff30

STIX ID: report--dcb44f54-d032-5fa7-a03f-2f5c4c83ff30

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: Divya

...
...

Netskope Threat Labs uncovered a global SEO-poisoning campaign distributing roughly 5,000 malicious PDFs across ~260 domains that embed fake CAPTCHA images to redirect victims to phishing pages (for payment and credential theft) and, in ~8% of cases, to PowerShell/MSHTA-based delivery of Lumma Stealer; the campaign has affected over 1,150 organizations and ~7,000 users across technology, financial services, and manufacturing, and abuses reputable CDNs and document repositories to evade detection, prompting recommendations for advanced URL filtering, PowerShell restrictions, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.