logo

Fake CAPTCHA websites hijack your clipboard to install information stealers

ID: c41017db-7557-5cbe-b3cd-7c95c9df10a8

STIX ID: report--c41017db-7557-5cbe-b3cd-7c95c9df10a8

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2025-03-10

Date Updated: 2026-04-28

...
...

This report details a widespread clipboard-hijacking technique where malicious websites trick users into allowing clipboard writes and instruct them to paste and execute a command (commonly an mshta call) in Windows Run; mshta then retrieves an encoded payload (often an encoded PowerShell script) that deploys info-stealers such as Lumma Stealer and SecTopRAT. The write-up outlines the attack flow, examples of file types used as lures, and practical mitigations including disabling JavaScript, using anti‑malware/browser-blocking extensions, and cautious user behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.