Expel Quarterly Threat Report Q3 2024, volume II: CAPTCHA trick or treat
ID: 117cee28-b6a4-51e5-911b-6c161091a357
STIX ID: report--117cee28-b6a4-51e5-911b-6c161091a357
Feed Name: Expel Blog
Expel Q3 Volume II documents a rising social-engineering trend where malicious or compromised webpages display fake CAPTCHAs or spoofed application alerts that automatically copy base64-encoded PowerShell to a user’s clipboard and instruct them to paste and execute it; the retrieved payloads commonly include infostealers and loaders (examples: Lumma, Lactrodectus, Brute Ratel). The report provides observed examples (including delivery via sketchy streaming sites, GitHub comment abuse, and weaponized HTML attachments), discusses why the tactic is effective, and lists mitigations such as restricting admin privileges, deploying EDR, constraining PowerShell, enabling script block logging, using WDAC/AppLocker, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
