PULSE NAME
Malicious CAPTCHA delivers Lumma and Amadey Trojans
WHITE AlienVault 2024-10-29 Modified: 2024-10-29
5
IOCs
LOW VOLUME
An adware campaign targets online users by presenting them with fake CAPTCHA or update prompts, tricking them into running malicious PowerShell commands that deploy credential-stealing malware like Lumma and Amadey. The attackers leverage ad networks to redirect victims to compromised sites hosting these social engineering lures. Once executed, Lumma abuses legitimate BitLocker functionality to harvest cryptocurrency wallets, passwords, and browser data, while Amadey gathers credentials and can deploy Remcos remote access trojan.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Lumma Amadey - S1025 Remcos
Indicators of Compromise (5)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 525abe8da7ca32f163d93268c509a4c5 2024-10-29
FileHash-MD5 e3274bc41f121b918ebb66e2f0cbfe29 2024-10-29
FileHash-MD5 ee2ff2c8f49ca29fe18e8d18b76d4108 2024-10-29
FileHash-SHA1 59f706841db1ad174075bd529cc5b231a6bb6054 2024-10-29
FileHash-SHA256 210a9e063211abc76ee5d4b082a207ae20627021d0ec3131963a4a1822aaf9db 2024-10-29