Breaking
March 15, 2025

This devious phishing site repurposes legitimate web elements like CAPTCHA pages for malware distribution udinmwenefosa@gmail.com (Efosa Udinmwen) | usagoldmines.com


  • Phishing campaign mimics CAPTCHA to deliver hidden malware commands
  • PowerShell command hidden in verification leads to Lumma Stealer attack
  • Educating users on phishing tactics is key to preventing such attacks

CloudSek has uncovered a sophisticated method for distributing the Lumma Stealer malware which poses a serious threat to Windows users.

This technique relies on deceptive human verification pages that trick users into unwittingly executing harmful commands.

While the campaign primarily focuses on spreading the Lumma Stealer malware, its methodology could potentially be adapted to deliver a wide variety of other malicious software.

How the phishing campaign works

The campaign employs trusted platforms such as Amazon S3 and various Content Delivery Networks (CDNs) to host phishing sites, utilizing modular malware delivery where the initial executable downloads additional components or modules, thereby complicating detection and analysis efforts.

The infection chain in this phishing campaign begins with threat actors luring victims to phishing websites that mimic legitimate Google CAPTCHA verification pages. These pages are presented as a necessary identity verification step, tricking users into believing they are completing a standard security check.

The attack takes a more deceptive turn once the user clicks the “Verify” button. Behind the scenes, a hidden JavaScript function activates, copying a base64-encoded PowerShell command onto the user’s clipboard without their knowledge. The phishing page then instructs the user to perform an unusual series of steps, such as opening the Run dialog box (Win+R) and pasting the copied command. These instructions, once followed, cause the PowerShell command to be executed in a hidden window, which is invisible to the user, making detection by the victim almost impossible.

The hidden PowerShell command is the crux of the attack. It connects to a remote server to download additional content such as a text file (a.txt) containing instructions for retrieving and executing the Lumma Stealer malware. Once this malware is installed on the system, it establishes connections with attacker-controlled domains. This allows attackers to compromise the system, steal sensitive data, and potentially launch further malicious activities.

To guard against this phishing campaign, both users and organizations must prioritize security awareness and implement proactive defences. A critical first step is user education.

The deceptive nature of these attacks – disguised as legitimate verification processes – shows the importance of informing users about the dangers of following suspicious prompts, especially when asked to copy and paste unknown commands. Users need to be trained to recognize phishing tactics and question unexpected CAPTCHA verifications or unfamiliar instructions that involve running system commands.

In addition to education, deploying robust endpoint protection is essential for defending against PowerShell-based attacks. Since attackers in this campaign rely heavily on PowerShell to execute malicious code, organizations should ensure that their security solutions are capable of detecting and blocking these activities. Advanced endpoint protection tools with behavioural analysis and real-time monitoring can detect unusual command executions, helping to prevent the malware from being downloaded and installed.

Organizations should also take a proactive approach by monitoring network traffic for suspicious activity. Security teams need to pay close attention to connections with newly registered or uncommon domains, which are often used by attackers to distribute malware or steal sensitive data.

Finally, keeping systems updated with the latest patches is a crucial defense mechanism. Regular updates ensure that known vulnerabilities are addressed, limiting the opportunity for attackers to exploit outdated software in their efforts to distribute malware like Lumma Stealer.

“This new tactic is particularly dangerous because it plays on users’ trust in widely recognized CAPTCHA verifications, which they encounter regularly online. By disguising malicious activity behind what seems like a routine security check, attackers can easily trick users into executing harmful commands on their systems. What’s more concerning is that this technique, currently distributing the Lumma Stealer, could be adapted to spread other types of malware, making it a highly versatile and evolving threat,” said Anshuman Das, Security Researcher at CloudSEK.

You may also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Crew-10 launches, finally clearing the way for Butch and Suni to fly home Eric Berger | usagoldmines...

Eight Tips for Getting the Most Out of Apple's Focus Modes Juli Clover | usagoldmines.com

ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthroug...

I visited the world’s first registered .com domain – and you won’t believe what it’s offering today ...

You Can Get a Lifetime of AdGuard's Family Plan on Sale for Just $16 Right Now Pradershika Sharma | ...

MacRumors Giveaway: Win an Apple Watch Ultra 2 and Charger From Lululook Juli Clover | usagoldmines....

US measles cases reach 5-year high; 15 states report cases, Texas outbreak grows Beth Mole | usagold...

2025 iPad Air hands-on: Why mess with a good thing? Samuel Axon | usagoldmines.com

This is the world's first 8K 5G 360 degrees camera - and it is also weatherproof | usagoldmines.com

Everything you say to your Echo will be sent to Amazon starting on March 28 Scharon Harding | usagol...

Best laptops under $500: Best overall, best battery life, and more | usagoldmines.com

So long, Google Assistant. It’s Gemini’s world now | usagoldmines.com

OnePlus Watch 3 Review: It’s Probably the Wear OS Watch to Beat Kellen | usagoldmines.com

This Massive LG Smart TV Is Over $500 Off Daniel Oropeza | usagoldmines.com

Here's a Look Inside the New M4 MacBook Air Juli Clover | usagoldmines.com

Apple's $349 A16 iPad Supports Final Cut Pro Juli Clover | usagoldmines.com

Thousands of healthcare records exposed online, including private patient information | usagoldmine...

Coding AI tells developer to write it himself erichs211@gmail.com (Eric Hal Schwartz) | usagoldmines...

The big Siri Apple Intelligence delay proves that maybe we really don't know Apple at all lance.ulan...

Researchers astonished by tool’s apparent success at revealing AI’s hidden motives Benj Edwards | us...

11 Ways to Automate Your Life (and Get Back More Free Time) Jeff Somers | usagoldmines.com

Apple Reassures Siri Team Members Feeling Disappointed and Embarrassed by Apple Intelligence Delay J...

Details of Nvidia's fastest video card ever leak; RTX Pro 6000 Blackwell GPU will have 96GB GDDR7 EC...

Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavywei...

Google Messages could soon follow WhatsApp with an upgrade that makes it much easier to join group c...

Apple Original Films will take you behind-the-scenes of a racing cockpit in new thrilling F1 trailer...

Small charges in water spray can trigger the formation of key biochemicals Jacek Krywko | usagoldmin...

RCS texting updates will bring end-to-end encryption to green bubble chats Andrew Cunningham | usago...

I threw away Audible’s app, and now I self-host my audiobooks Lee Hutchinson | usagoldmines.com

End of Life: Gemini will completely replace Google Assistant later this year Ryan Whitwam | usagoldm...

Windows 11 24H2’s March update is riddled with failures and crashes | usagoldmines.com

It’s Official: Google Assistant is Dead, Replaced by Gemini Kellen | usagoldmines.com

My Favorite Amazon Deal of the Day: The Apple AirPods 4 Daniel Oropeza | usagoldmines.com

Best Apple Deals of the Week: Launch Discounts Hit New iPad, iPad Air, and MacBook Air, Plus AirPods...

Apple Launches 'Surveyor' App for Apple Maps Data Collection Juli Clover | usagoldmines.com

My dream Hasselblad camera is getting a sequel soon, according to new leaks – here are 5 upgrades I’...

AI agents can be hijacked to write and send phishing attacks | usagoldmines.com

To avoid the Panama Canal, Relativity Space is moving some operations to Texas Eric Berger | usagold...

Tesla urges overhaul of Trump tariffs hurting EV industry Ashley Belanger | usagoldmines.com

Sony drops an unexpected Blu-ray surprise! | usagoldmines.com

Nvidia boasts ‘twice as many’ RTX 50 GPUs shipped versus last gen | usagoldmines.com

The Spectrum review: Relive the ZX Spectrum’s 80s gaming glories | usagoldmines.com

How to Get Free COVID Tests in Bulk for Your Community Beth Skwarecki | usagoldmines.com

iOS 19 Might Add Live Translation for AirPods Jake Peterson | usagoldmines.com

The Running Gear You Should Splurge On (and When You Can Go Cheap) Meredith Dietz | usagoldmines.com

Hands-On With Apple's New M3 iPad Air Juli Clover | usagoldmines.com

Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock | usago...

AirPods could catch up with Samsung buds with a live translation free upgrade in iOS 19 | usagoldmi...

You can now use an IPv4 address as business collateral - and it could be worth millions | usagoldmi...

Sony launches new version of the best cheap 4K Blu-ray player that drops the streaming tech – but th...

NymVPN is now live – here's everything you need to know chiara.castro@futurenet.com (Chiara Castro) ...

Google agrees with OpenAI that copyright has no place in AI development Ryan Whitwam | usagoldmines....

US measles outlook is so bad health experts call for updating vaccine guidance Beth Mole | usagoldmi...

Used Tesla prices tumble as embarrassed owners look to sell Jonathan M. Gitlin | usagoldmines.com

Why you should buy a cheaper laptop and upgrade the storage yourself | usagoldmines.com

Logitech’s wireless charging mousepad is the best absurd PC luxury I’ve ever owned | usagoldmines.c...

It looks like Asus redesigned the scratchy PCIe slots on its motherboards | usagoldmines.com

This $15 indoor security camera doubles as a baby monitor (40% off) | usagoldmines.com

Whoa! This 180Hz IPS gaming monitor is seriously just $80 right now | usagoldmines.com

Samsung March Updates Hit Galaxy S23 Series, Fold 6, Flip 6, More Kellen | usagoldmines.com

I've Spent Years Writing Streaming Guides, and Yes, for Movie Fans, Streaming Is Getting Worse Ross ...

The MacRumors Show: Apple Intelligence Comes Under Fire Hartley Charlton | usagoldmines.com

GitLab has patched a host of worrying security issues | usagoldmines.com

The world's leading website builder aims to save businesses time with new tool | usagoldmines.com

Apple will finally enable encrypted RCS messages between iOS and Android, and it's about time jamie....

Apple Intelligence is a fever dream that I bet Apple wishes we could all forget about john-anthony.d...

Android 16 Beta 3 has arrived – here are the 4 features I think will be the most useful jamie.richar...

Another day, another dreadful PC port - Rise of the Ronin joins the list of woeful PC launches with ...

Juniper patches security flaws which could have let hackers take over your router | usagoldmines.co...

Scoop: Origami measuring spoon incites fury after 9 years of Kickstarter delay hell Ashley Belanger ...

‘We’re getting scalped’: System integrator says even he can’t buy 5090 cards at MSRP | usagoldmines...

Save $250 on MSI’s RTX 4070 laptop with 32GB RAM right now | usagoldmines.com

Fullscreen vs. borderless? Why I stopped tripping on the gaming mode question | usagoldmines.com

I built a maxed-out Raspberry Pi 5 PC with an SSD for under $200. You can, too! | usagoldmines.com

It’s Pi Day! Grab this Raspberry Pi 5 starter kit on sale while you can | usagoldmines.com

10 surprisingly practical Raspberry Pi projects anybody can do | usagoldmines.com

New RCS Universal Profile 3.0 Adds End-to-End Encryption, Apple and Google Both Included Kellen | us...

Why Microsoft Is Phasing Out Their Remote Desktop App (and What to Use Instead) David Nield | usagol...

iPhone 17 Pro Max Rumors Allegedly Refer to 'iPhone 17 Ultra' Model Tim Hardwick | usagoldmines.com

Volt Typhoon threat group had access to American utility networks for the best part of a year luke.h...

Quordle hints and answers for Saturday, March 15 (game #1146) | usagoldmines.com

7 new movies and TV shows to stream on Netflix, Prime Video, Max, and more this weekend (March 14) t...

NYT Strands hints and answers for Saturday, March 15 (game #377) | usagoldmines.com

NYT Connections hints and answers for Saturday, March 15 (game #643) | usagoldmines.com

I think Asus could be the perfect partner for an Xbox handheld – but I have questions | usagoldmine...

Modernizing data centers: an efficient path forward | usagoldmines.com

New Reddit controls let you block your most-hated advertisers for a year Scharon Harding | usagoldmi...

I stopped using Alexa long ago. Here are 6 ways Alexa+ could lure me back | usagoldmines.com

This Ryzen 9 mini PC with 24GB RAM is a bargain for $359 | usagoldmines.com

'Redact' Can Delete Your Posts From 28 Different Social Networks Justin Pot | usagoldmines.com

Apple Music Classical is now available on the web, but its Mac app is still nowhere in sight rowan.d...

US government warns Medusa ransomware has hit hundreds of critical infrastructure targets | usagold...

Believe it, baby: Ted Lasso season 4 is officially in development for Apple TV+ – and Jason Sudeikis...

Best Chromebooks 2025: Best overall, best battery life, and more | usagoldmines.com

Best monitors 2025: Gaming, 4K, HDR, and more | usagoldmines.com

Google issues a fix for Chromecast ‘untrusted’ bug | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

I never thought a Microsoft Edge plugin could improve gaming. I was wrong | usagoldmines.com

Apple Wallet Gets Deeper Integration With PayPal's Debit Card This Year Joe Rossignol | usagoldmines...

'Ted Lasso' Fourth Season Confirmed by Series Star Jason Sudeikis Tim Hardwick | usagoldmines.com

Leave a Reply