
Fake CAPTCHA Runs Malware
Source: YouTube · John Hammond · published Sep 17, 2024 · 22:47
The video exposes a deceptive phishing campaign using fake "verify you are human" capture pages to socially engineer victims into copying and pasting malicious PowerShell commands, leading to the execution of an LMA (Lumma) stealer. 0:00
Key Takeaways:
• A user was lured via a redirect chain from ads to a fake capture page (4.bcn.net) that instructed them to press Win + R, Ctrl + V, and Enter to "verify" they are human 1:33.
• The clipboard-paste action executed a base64-encoded PowerShell payload using mshta, which downloaded and ran a Lumma info-stealing malware 2:42.
• The malware injected into legitimate Windows binaries like bitlocker.exe and searchindexer.exe to evade detection 6:25.
• Forensic analysis of the Windows Registry’s Run MRU list can reveal the malicious command history and confirm user compromise 13:00.
• The attack is part of a broader campaign observed across multiple security teams (Unit 42, Proof Point, Huntress) with shared indicators and domains 10:08.
This attack highlights how simple, cutesy social engineering can bypass security awareness and lead to full compromise. 21:45
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
our security operations center has recently seen a number of investigative cases where the origin and start of malicious code that runs seemingly comes from absolutely nowhere and this is encoded Powershell it's a small oneliner to kick things off but there wasn't a clear starting process or persistence mechanism or initial access Vector other than just explore. exe like your desktop we could see the process invocation and the commands that were ran but where did this all kind of come from so our sock analyst dug a little bit deeper and took a look in the users's web browser history it seems like this poor user the victim the Target in this case was unfortunately following through a redirect chain all online maybe from a ad or popup or something that just flew open on their browser and may…