PULSE NAME
Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising
WHITE AlienVault 2024-12-18 Modified: 2024-12-19
32
IOCs
MEDIUM VOLUME
A large-scale fake captcha campaign has been distributing Lumma info-stealer malware through malvertising techniques. The campaign, relying on a single ad network, delivers over 1 million daily ad impressions, causing thousands of daily victims to lose their accounts and money. The malicious activity is propagated through a network of 3,000+ content sites funneling traffic. The campaign uses deceptive captcha pages that trick users into executing PowerShell commands, instantly installing stealer malware. The ad network Monetag, a subsidiary of PropellerAds, is identified as the primary facilitator. The threat actors leverage services like BeMob for cloaking, showcasing the fragmented accountability in the ad ecosystem. The campaign's success highlights the need for stronger proactive measures in ad networks and the importance of user caution when encountering free content online.
Indicators of Compromise (32)
All domain FileHash-MD5 hostname
TYPEINDICATORDESCRIPTIONCREATED
domain chromeupdates.com 2024-12-18
FileHash-MD5 7a0525921ff54f1193db83d7303c6ee8 2024-12-18
domain adstrails.com 2024-12-18
domain boltsreach.com 2024-12-18
domain cdn-downloads-now.xyz 2024-12-18
domain fiare-activity.com 2024-12-18
domain fingerboarding.com 2024-12-18
domain foodrailway.cfd 2024-12-18
domain glidronix.com 2024-12-18
domain impressflow.com 2024-12-18
domain insigelo.com 2024-12-18
domain marimarbahamas.me 2024-12-18
domain mediamanagerverif.com 2024-12-18
domain nettrilo.com 2024-12-18
domain nowuseemi.com 2024-12-18
domain offerztodayforu.com 2024-12-18
domain privatemeld.com 2024-12-18
domain restoindia.me 2024-12-18
domain satisfiedweb.com 2024-12-18
domain secureporter.com 2024-12-18
domain servinglane.com 2024-12-18
domain sheenglathora.com 2024-12-18
domain stephighs.com 2024-12-18
domain taketheright.com 2024-12-18
domain techstalone.com 2024-12-18
domain tracksvista.com 2024-12-18
domain travelwithandrew.xyz 2024-12-18
domain tunneloid.com 2024-12-18
domain westreamdaily.com 2024-12-18
domain yourtruelover.com 2024-12-18
hostname sos-ch-gva-2.sos-cdn.net 2024-12-18
hostname xxxx.bmtrck.com 2024-12-18