logo

Malicious ads push Lumma infostealer via fake CAPTCHA pages

ID: 396d029b-cbdf-503c-b0b1-68b8799db2cb

STIX ID: report--396d029b-cbdf-503c-b0b1-68b8799db2cb

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-12-16

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Guardio Labs and Infoblox researchers identified a large-scale malvertising campaign dubbed “DeceptionAds” that leveraged the Monetag ad network to push fake CAPTCHA pages which silently copy a malicious PowerShell command to victims' clipboards; when executed via the Windows Run dialog the command installs the Lumma Stealer info-stealer, which exfiltrates browser credentials, cookies, crypto wallets and sensitive files. The campaign used cloaking (BeMob) to evade moderation, delivered over a million daily ad impressions across thousands of sites (notably pirated streaming/software portals), was partially disrupted by ad platforms but showed attempts to resurface, and poses significant risk to end users and organizations due to credential theft and downstream fraud or breaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.