Unmasking the Danger: Lumma Stealer Malware Exploits Fake CAPTCHA Pages
ID: 66f20a70-3ca3-5c93-91cf-a57b57648ede
STIX ID: report--66f20a70-3ca3-5c93-91cf-a57b57648ede
Feed Name: CloudSEK Blog
**Executive Summary:** This report details a global campaign distributing the Lumma Stealer via fake CAPTCHA/human-verification web pages that copy a Base64-encoded PowerShell command to the clipboard; when pasted into the Windows Run dialog it executes and retrieves a downloader (dengo.zip) from attacker-controlled infrastructure, ultimately installing an infostealer and contacting command-and-control domains. The analysis includes multiple malicious URLs, an IP address (165.227.121.41), file names and SHA1 hashes, observations about CDN/S3 hosting and clipboard-based evasion, and practical mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
