Tricky CAPTCHA Caught Dropping Lumma Stealer Malware
ID: 4b3b9c1b-acdf-5781-876f-ce611b31dc71
STIX ID: report--4b3b9c1b-acdf-5781-876f-ce611b31dc71
Feed Name: Dark Reading
Date Published: 2024-10-22
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Lumma Stealer is being distributed in a new campaign that lures victims with fake CAPTCHA verification pages; when users complete the verification the page triggers a PowerShell command that downloads an initial malware stager. Researchers note the stealer’s adaptability—previous 2024 delivery methods included weaponized YouTube content, hijacked Facebook pages, and scams targeting gamers—and advise continuous monitoring, updated detection rules, and coordinated threat intelligence and incident response to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
