Tricky CAPTCHA Caught Dropping Lumma Stealer Malware (www.darkreading.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 23 Oct 11:43
https://sh.itjust.works/post/27042332

#cybersecurity

threaded - newest

sylver_dragon@lemmy.world on 24 Oct 00:30 collapse

Seen this one in my work environment. Confusing as heck the first time. It looks like explorer.exe in the context of the local user starts PowerShell.exe with a command line involving an Invoke-WebRequest piping the download into an Invoke-Expression (usually the shorter iex alias). No .lnk or .js file involved. Just explorer, PowerShell, infected.