Lumma Stealer Malware Being Spread to Windows Devices via Fake Human Verification Pages, CloudSEK Says

These fake human verification pages instruct users to run hidden commands to enable the downloading of the malware.

Advertisement
Written by Akash Dutta, Edited by Siddharth Suvarna | Updated: 19 September 2024 17:13 IST
Highlights
  • Content Delivery Networks (CDNs) are being used to trick users
  • Lumma Stealer is an information-stealing malware
  • Researchers have found many phishing websites distributing the malware

So far Lumma Stealer is the only malware known to be using this method

Photo Credit: Pexels/Sora Shimazaki

Lumma Stealer, a recently identified information-stealing malware, is being distributed to users via fake human verification pages. According to researchers at the cybersecurity firm CloudSEK, the malware is targeting Windows devices and is designed to steal sensitive information from the infected device. Concerningly, researchers have discovered multiple phishing websites which are deploying these fake verification pages to trick users into downloading the malware. CloudSEK researchers have warned organisations to implement endpoint protection solutions and to train employees and users about this new social engineering tactic.

Lumma Stealer Malware Being Distributed Using New Phishing Technique

According to the CloudSEK report, multiple active websites were found to be spreading the Lumma Stealer malware. The technique was first discovered by Unit42 at Palo Alto Networks, a cybersecurity firm, but the scope of the distribution chain is now believed to be much larger than previously assumed.

Advertisement

The attackers have set up various malicious websites and have added a fake human verification system, resembling the Google Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA) page. However, unlike the regular CAPTCHA page where users have to check a few boxes or perform similar pattern-based tasks to prove they are not a bot, the fake pages instruct the user to run some unusual commands.

In one instance, the researchers spotted a fake verification page asking users to execute a PowerShell script. PowerShell scripts contain a series of commands that can be executed in the Run dialog box. In this case, the commands were found to fetch the content from the a.txt file hosted on a remote server. This prompted a file to be downloaded and extracted on the Windows system, infecting it with Lumma Stealer.

Advertisement

The report also listed the malicious URLs which were spotted distributing the malware to unsuspecting users. However, this is not the full list and there might be more such websites carrying out the attack.

  • hxxps[://]heroic-genie-2b372e[.]netlify[.]app/please-verify-z[.]html
  • hxxps[://]fipydslaongos[.]b-cdn[.]net/please-verify-z[.]html
  • hxxps[://]sdkjhfdskjnck[.]s3[.]amazonaws[.]com/human-verify-system[.]html
  • hxxps[://]verifyhuman476[.]b-cdn[.]net/human-verify-system[.]html
  • hxxps[://]pub-9c4ec7f3f95c448b85e464d2b533aac1[.]r2[.]dev/human-verify-system[.]html
  • hxxps[://]verifyhuman476[.]b-cdn[.]net/human-verify-system[.]html
  • hxxps[://]newvideozones[.]click/veri[.]html
  • hxxps[://]ch3[.]dlvideosfre[.]click/human-verify-system[.]html
  • hxxps[://]newvideozones[.]click/veri[.]html
  • hxxps[://]ofsetvideofre[.]click

The researchers also observed that content delivery networks (CDNs) were being used to spread these fake verification pages. Further, the attackers were spotted using base64 encoding and clipboard manipulation to evade demonstration. It is also possible to distribute other malware using the same technique, although such instances have not been seen so far.

Advertisement

Since the modus operandi of the attack is based on phishing techniques, no security patch can prevent devices from getting infected. However, there are some steps users and organisations can take to safeguard against the Lumma stealer malware.

As per the report, users and employees should be made aware of this phishing tactic to help them not fall for it. Additionally, organisations should implement and maintain reliable endpoint protection solutions to detect and block PowerShell-based attacks. Further, regularly updating and patching systems to reduce the vulnerabilities that Lumma Stealer malware can exploit should also help.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Vivo X300 E Launch Date Confirmed; Pre-Orders Now Live in China
  2. Google's Fitbit Air Spotted on Amazon India Ahead of Official Launch
  3. Here's How the Redmi Watch 6 Active, Watch 6 Lite Could Cost
  4. Moto Pad 70 Groove Launching in India on July 31: Here's What It Offers
  5. Samsung Galaxy Z Fold 8 Fresh Renders Leaked Online Just Ahead of Launch
  6. Samsung Announces 'Back to School' Deals Across These Devices in India
  1. Tecno Camon 50 Ultra 5G Goes on Sale in India With Dimensity 7400 Ultimate SoC: Price, Offers
  2. Redmi Watch 6 Active, Watch 6 Lite Price, Key Specifications, and Other Details Leaked Online
  3. Samsung Galaxy Z Fold 8 Fresh Renders Leaked Online Just Ahead of Galaxy Unpacked Event
  4. Samsung Galaxy Watch 9 Leak Reveals Major Chipset Upgrade Before Galaxy Unpacked
  5. Samsung Galaxy S26 FE, Galaxy Tab S12 Reportedly Spotted in Google App Listing, Hinting at Imminent Launch
  6. iQOO 16T Tipped to Feature Next-Generation MediaTek or Qualcomm Chip; Key Specifications Leak
  7. Oppo Find X10 Series Leak Reveals Chipset, Display Details; Find X10 Pro Max Tipped to Get Dimensity 9600 Pro
  8. Redmi Note 17 India Launch Date Leaked as Tipster Confirms Indian Variant’s Key Specifications
  9. Samsung Galaxy Z Fold 8, Z Fold 8 Ultra, Z Flip 8, Galaxy Watch 9 Prices Leak Ahead of Galaxy Unpacked
  10. Google's Fitbit Air Spotted on Amazon India Ahead of Official Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.