logo

Infostealer LummaC2 Spreading Through Fake CAPTCHA Verification Page

ID: 6fcf3fcb-6a11-5703-a758-621c72bbc5a8

STIX ID: report--6fcf3fcb-6a11-5703-a758-621c72bbc5a8

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-01-07

Date Updated: 2026-04-26

Author: ATCP

...
...

This report describes LummaC2 distribution via fake CAPTCHA pages and phishing, where a malicious HTML/HTA executed by mshta retrieves an obfuscated AES-encrypted PowerShell loader that ultimately runs LummaC2; the malware exfiltrates browser and cryptocurrency data and includes a ClipBanker module that swaps clipboard wallet addresses. The report includes MD5 hashes and URLs for indicators of compromise and advises caution when interacting with unknown download or email sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.