Lunar Spider – Lotus V2 Loader Campaign Using Fake CAPTCHA Delivery and DLL Sideloading
ID: 8236479c-c145-5004-9c3c-d989b932e3b5
STIX ID: report--8236479c-c145-5004-9c3c-d989b932e3b5
Feed Name: Kudelski Security
Lunar Spider, a financially motivated cybercrime group active since at least 2017, is deploying the Lotus V2 loader via fake CAPTCHA drive-by campaigns that use a malicious PowerShell command to abuse WindowsInstaller.Installer, download an MSI, and achieve DLL sideloading through a legitimate Intel binary (igfxSDK.exe) which loads a malicious WTSAPI32.dll; operators also abuse stolen code-signing certificates to evade detection. The report includes IOCs (SHA256 hashes, certificate thumbprints, and C2 domains), maps observed TTPs to MITRE ATT&CK, and provides practical detection and hunting recommendations such as monitoring Run dialog use of LOLBins, MSI installations from remote sources, DLL hijacking patterns, and certificate-based pivots.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
