logo

Unmasking the Danger: Lumma Stealer Malware Exploits Fake CAPTCHA Pages

ID: 66f20a70-3ca3-5c93-91cf-a57b57648ede

STIX ID: report--66f20a70-3ca3-5c93-91cf-a57b57648ede

Feed Name: CloudSEK Blog

Threat Score
72/100

Date Published: 2024-09-19

Date Updated: 2026-04-27

...
...

**Executive Summary:** This report details a global campaign distributing the Lumma Stealer via fake CAPTCHA/human-verification web pages that copy a Base64-encoded PowerShell command to the clipboard; when pasted into the Windows Run dialog it executes and retrieves a downloader (dengo.zip) from attacker-controlled infrastructure, ultimately installing an infostealer and contacting command-and-control domains. The analysis includes multiple malicious URLs, an IP address (165.227.121.41), file names and SHA1 hashes, observations about CDN/S3 hosting and clipboard-based evasion, and practical mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.