, , ,

Fake CAPTCHA pages used to spread infostealer malware


  • Security researchers spot campaign to distribute Lumma Stealer malware
  • A fake CAPTCHA page comes with a JavaScript that copies malicious code into the clipboard
  • To “solve” the fake CAPTCHA, users are told to paste the code in CMD and run it

Fake CAPTCHA pages are being used to trick victims into downloading and running the Lumma infostealer malware.

Security researchers at Guardio Labs recently discovered a major malicious operation, targeting millions of people, called “DeceptionAds”.

The campaign abuses two legitimate services, the Monetag ad network and BeMob, a cloud-based performance tracking platform. It starts with fake ads, promoting things that appeal to the host site’s audience, such as fake offers, downloads, or different services – with pirate streaming and software platforms apparently among the most common themes.

Vane Viper

When the victim clicks on the ad, they are redirected to a fake CAPTCHA page through the BeMob cloaking service. This makes moderation difficult, since BeMob is a legitimate service, and as such, is not being removed from the Monetag ad network by default.

“By supplying a benign BeMob URL to Monetag’s ad management system instead of the direct fake captcha page, the attackers leveraged BeMob’s reputation, complicating Monetag’s content moderation efforts,” Nati Tal, head of Guardio Labs, said in a writeup.

The CAPTCHA page comes with a piece of JavaScript code that copies a malicious PowerShell one-line command into the clipboard. However, the victim still needs to paste that code into the CMD and run it, which is where the CAPTCHA “solution” comes in. To solve the CAPTCHA, users are required to bring up the Windows Run dialog, press CTRL+V (paste), and hit enter.

This runs the command that downloads and executes Lumma Stealer. The group behind the attack is called Vane Viper.

Lumma is a popular infostealer in the underground community. It is capable of stealing a wide range of sensitive information , including cryptocurrency wallets, browser data, email credentials, financial information, FTP client data, and system information.

When Monetag and BeMob were notified of the campaign, both companies stepped in to address the issue. Monetag removed 200 accounts, while BeMob terminated the campaign in four days.

Via BleepingComputer

You might also like

https://www.techradar.com/pro/security/fake-captcha-pages-used-to-spread-infostealer-malware


Leave a Reply

Your email address will not be published. Required fields are marked *

December 2024
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
3031  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 1010: The Densest State in the US – TikTok Ban, Drones Over Jersey, GM Quits Robotaxis This Week in Tech (Audio)

So You Want to Solve the NJ Drone Mystery? Our Expert Has Some Ideas Infowars Sale to The Onion Rejected by Federal Bankruptcy Judge Federal appeals court declines to temporarily block ban on TikTok, teeing up showdown at SCOTUS over controversial law WordPress parent company must stop blocking WP Engine, judge rules Crypto's Legacy Is Finally Clear Tech Industry and CEOs Curry Favor With Trump Ahead of His Inauguration AI Is Detecting More Breast Cancer Cases, Study Suggests Huge randomized trial of AI boosts discovery — at least for good scientists GM Calls It Quits on Mary Barra's $50 Billion Robotaxi Dream You Can Buy a Car on Amazon Now Host: Leo Laporte Guests: Cathy Gellis, Mike Elgan, and Emily Forlini Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: mintmobile.com/twit shopify.com/twit
  1. TWiT 1010: The Densest State in the US – TikTok Ban, Drones Over Jersey, GM Quits Robotaxis
  2. TWiT 1009: Andy Giveth & Bill Taketh Away – Trump's Tech Titans, Crypto Boom, TikTok's US Ban, Intel CEO Exits
  3. TWiT 1008: Internet Legal – Australia's Social Media Ban for Kids, Smart Home Nightmare, Bluesky's Ascent
  4. TWiT 1007: All the Hotdogs in the World – China's "Salt Typhoon" Hack, Google on the Chopping Block, Recall AI
  5. TWiT 1006: Underwater Alien Civilizations – Bluesky Growth, Tyson Vs. Paul, AI Granny