Infostealer LummaC2 Spreading Through Fake CAPTCHA Verification Page
ID: 6fcf3fcb-6a11-5703-a758-621c72bbc5a8
STIX ID: report--6fcf3fcb-6a11-5703-a758-621c72bbc5a8
Feed Name: ASEC
Threat Score
This report describes LummaC2 distribution via fake CAPTCHA pages and phishing, where a malicious HTML/HTA executed by mshta retrieves an obfuscated AES-encrypted PowerShell loader that ultimately runs LummaC2; the malware exfiltrates browser and cryptocurrency data and includes a ClipBanker module that swaps clipboard wallet addresses. The report includes MD5 hashes and URLs for indicators of compromise and advises caution when interacting with unknown download or email sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
