← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
“DeceptionAds” — Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising
Guardio Labs reported on a large-scale fake captcha campaign distributing Lumma Stealer that circumvents general security measures like Safe Browsing. The campaign relies entirely on a single ad network for propagation (malvertising), Monetag, a subsidiary of ProepllerAds previously tracked by Infoblox under the name “Vane Viper.” These ads, leveraging BeMob for tracking, receive over 1 million daily “impressions,” potentially causing thousands of daily infections of Lumma Stealer through a network of 3,000+ sites using Monetag scripts. The research dissects this campaign and provides insights into the malvertising industry’s infrastructure, tactics, and key players.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Lumma Stealer
Indicators of Compromise (1 / 191 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 7a0525921ff54f1193db83d7303c6ee8 | — | 2024-12-16 |