logo

Expel Quarterly Threat Report Q3 2024, volume II: CAPTCHA trick or treat

ID: 117cee28-b6a4-51e5-911b-6c161091a357

STIX ID: report--117cee28-b6a4-51e5-911b-6c161091a357

Feed Name: Expel Blog

Threat Score
65/100

Date Published: 2024-10-17

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

Expel Q3 Volume II documents a rising social-engineering trend where malicious or compromised webpages display fake CAPTCHAs or spoofed application alerts that automatically copy base64-encoded PowerShell to a user’s clipboard and instruct them to paste and execute it; the retrieved payloads commonly include infostealers and loaders (examples: Lumma, Lactrodectus, Brute Ratel). The report provides observed examples (including delivery via sketchy streaming sites, GitHub comment abuse, and weaponized HTML attachments), discusses why the tactic is effective, and lists mitigations such as restricting admin privileges, deploying EDR, constraining PowerShell, enabling script block logging, using WDAC/AppLocker, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.