logo

Lunar Spider – Lotus V2 Loader Campaign Using Fake CAPTCHA Delivery and DLL Sideloading

ID: 8236479c-c145-5004-9c3c-d989b932e3b5

STIX ID: report--8236479c-c145-5004-9c3c-d989b932e3b5

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2025-06-27

Date Updated: 2026-07-23

...
...

Lunar Spider, a financially motivated cybercrime group active since at least 2017, is deploying the Lotus V2 loader via fake CAPTCHA drive-by campaigns that use a malicious PowerShell command to abuse WindowsInstaller.Installer, download an MSI, and achieve DLL sideloading through a legitimate Intel binary (igfxSDK.exe) which loads a malicious WTSAPI32.dll; operators also abuse stolen code-signing certificates to evade detection. The report includes IOCs (SHA256 hashes, certificate thumbprints, and C2 domains), maps observed TTPs to MITRE ATT&CK, and provides practical detection and hunting recommendations such as monitoring Run dialog use of LOLBins, MSI installations from remote sources, DLL hijacking patterns, and certificate-based pivots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.