cognitive cybersecurity intelligence

News and Analysis

Search

Fake CAPTCHA Pages Used by Lumma Stealer to Spread Fileless Malware

Lumma Stealer malware, available through a Malware-as-a-Service model, is using fake CAPTCHA pages to trick users into executing a persistent attack. The Qualys Threat Research Unit discovered that clicking the CAPTCHA ‘I’m not a robot’ button activates a malicious PowerShell command that downloads malware onto the target machine. It then looks for sensitive files and data linked to passwords and cryptocurrency, which it sends to a command and control server.

Source: hackread.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts