logo

Analyzing LummaStealer’s FakeCAPTCHA Delivery Tactics

ID: 7a07de59-6946-5c3d-9193-fdb096c811e8

STIX ID: report--7a07de59-6946-5c3d-9193-fdb096c811e8

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Binary Defense ARC Labs analyzed active LummaStealer (LummaC2) campaigns that employ a FakeCAPTCHA social-engineering method to trick victims into pasting and executing mshta/PowerShell commands; these commands download script files masquerading as .mp4/.png which deliver an info-stealer that exfiltrates browser credentials, crypto wallets, and system identifiers, and the report includes technical details and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.