
A new phishing campaign utilizing Windows PowerShell and fake CAPTCHA tests has been identified. The campaign is designed to trick users into downloading and installing the Lumma Stealer malware, which steals credentials. According to McAfee researchers, the fake security test manipulates users into believing they are completing a legitimate CAPTCHA. This method has been particularly effective against users searching for pirated PC games. The phishing campaign has scary potential and has been seen in attempts sent via Paperless Post.
worst phishing scam ever https://t.co/WxMw29NiWK
Threat Actors Shift to JavaScript-Based Phishing Attacks https://t.co/IyfGum2b9j
There's been a rise in fake #CAPTCHA tests that are tricking users looking for pirated PC games into installing #malware. https://t.co/Bl8edKmBXu