Fake CAPTCHA Campaign: Inside a Multi-Stage Stealer Assault
ID: 8fcaa4ca-095a-5965-b564-dacbe1fba391
STIX ID: report--8fcaa4ca-095a-5965-b564-dacbe1fba391
Feed Name: LevelBlue SpiderLabs Blog
Date Published: 2026-03-19
Date Updated: 2026-04-28
Author: Shabtay Barel, Serhii Melnyk, Rodel Mendrez
This report documents an active, modular fileless malware campaign that compromises hundreds of legitimate websites to serve fake CAPTCHA pages which use clipboard hijacking and social engineering to get victims to run PowerShell commands; the in-memory chain (Donut shellcode and staged loaders) delivers rotating commodity stealers (Lumma, Vidar, Aura, Rhadamanthys) and a cryptocurrency clipboard hijacker, with infrastructure links to a large cluster of fake crypto-exchange sites and indicators suggesting a Russian-nexus actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
