← Back to Pulse Feed
PULSE DETAIL
An adware campaign targets online users by presenting them with fake CAPTCHA or update prompts, tricking them into running malicious PowerShell commands that deploy credential-stealing malware like Lumma and Amadey. The attackers leverage ad networks to redirect victims to compromised sites hosting these social engineering lures. Once executed, Lumma abuses legitimate BitLocker functionality to harvest cryptocurrency wallets, passwords, and browser data, while Amadey gathers credentials and can deploy Remcos remote access trojan.
MITRE ATT&CK & Malware Families
Indicators of Compromise (5)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 525abe8da7ca32f163d93268c509a4c5 | — | 2024-10-29 | |
| FileHash-MD5 | e3274bc41f121b918ebb66e2f0cbfe29 | — | 2024-10-29 | |
| FileHash-MD5 | ee2ff2c8f49ca29fe18e8d18b76d4108 | — | 2024-10-29 | |
| FileHash-SHA1 | 59f706841db1ad174075bd529cc5b231a6bb6054 | — | 2024-10-29 | |
| FileHash-SHA256 | 210a9e063211abc76ee5d4b082a207ae20627021d0ec3131963a4a1822aaf9db | — | 2024-10-29 |