logo

Fake CAPTCHA Campaign: Inside a Multi-Stage Stealer Assault

ID: 8fcaa4ca-095a-5965-b564-dacbe1fba391

STIX ID: report--8fcaa4ca-095a-5965-b564-dacbe1fba391

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-04-28

Author: Shabtay Barel, Serhii Melnyk, Rodel Mendrez

...
...

This report documents an active, modular fileless malware campaign that compromises hundreds of legitimate websites to serve fake CAPTCHA pages which use clipboard hijacking and social engineering to get victims to run PowerShell commands; the in-memory chain (Donut shellcode and staged loaders) delivers rotating commodity stealers (Lumma, Vidar, Aura, Rhadamanthys) and a cryptocurrency clipboard hijacker, with infrastructure links to a large cluster of fake crypto-exchange sites and indicators suggesting a Russian-nexus actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.