This Windows PowerShell Phish Has Scary Potential
ID: c7f94cc5-9472-564e-bdd6-8557473e2f1f
STIX ID: report--c7f94cc5-9472-564e-bdd6-8557473e2f1f
Feed Name: Krebs on Security
Threat Score
A phishing campaign impersonating GitHub lures users to a malicious site that presents a fake "Verify You Are Human" CAPTCHA; following the site's instructions to press Win+R, Ctrl+V and Enter launches PowerShell which downloads and runs l6e.exe (identified as Lumma Stealer), a credential‑stealing malware. The article highlights the social‑engineering technique targeting less technical Windows users and links to a VirusTotal analysis of the payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
