logo

This Windows PowerShell Phish Has Scary Potential

ID: c7f94cc5-9472-564e-bdd6-8557473e2f1f

STIX ID: report--c7f94cc5-9472-564e-bdd6-8557473e2f1f

Feed Name: Krebs on Security

Threat Score
60/100

Date Published: 2024-09-19

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

A phishing campaign impersonating GitHub lures users to a malicious site that presents a fake "Verify You Are Human" CAPTCHA; following the site's instructions to press Win+R, Ctrl+V and Enter launches PowerShell which downloads and runs l6e.exe (identified as Lumma Stealer), a credential‑stealing malware. The article highlights the social‑engineering technique targeting less technical Windows users and links to a VirusTotal analysis of the payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.