Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Verification CAPTCHA Spreads Malware to Windows Users
Facebook   X   LinkedIn   Email

Verification CAPTCHA Spreads Malware to Windows Users

January 27, 2025

That familiar CAPTCHA challenge we’re asked to do proving we’re not robots is getting some Windows users in trouble. Hackers are using their own bogus CAPTCHA pages to sneak malware onto Windows devices. It looks like this is one-time that Windows users may pay the price for not being a robot. The good news is, there’s a way to tell when you’re being targeted.

Whether we’re clicking a box, choosing frames where an item is showing, or typing-in random letters, most of us are used to CAPTCHA as security steps proving we’re human. And now, this is the vehicle hackers are focusing on to deliver Lumma Stealer, an info-stealing malware. This successful campaign has been spotted in various places across the globe and it’s growing fast.

What Lumma Stealer Steals

Like a lot of info-stealers, Lumma goes after device and system data including your personally identifiable information (PII). Aside from stealing documents, pics and videos from compromised devices, Lumma also steals PII like usernames and passwords, and payment card and banking details. In short, Lumma Stealer steals what’s needed to hijack your privacy, money, and your identity.

CAPTCHA Crime Clues

There are clues when CAPTCHA verification pages aren’t what they claim to be. Users are unknowingly sent to a fake CAPTCHA page taking just one click to start a chain reaction releasing Lumma Stealer. Then, the usual one or two “prove you’re a human” requirements are replaced with a number of seemingly never-ending verification hoops to jump through. That’s the point where this CAPTCHA crime is on a roll installing Lumma through your system.

So, when your Windows CAPTCHA starts adding an unusual amount of verification steps, it’s time to stop following them. You already know you’re human and proving it with CAPTCHA should never take more than one or two Windows commands.


AI Scrapes Your Data For Training: Take Steps To Protect Your Data

Your Security

AI Scrapes Your Data For Training: Take Steps To Protect Your Data

Large language models like ChatGPT have introduced complexity to the evolving online threat landscape. Cybercriminals are increasingly using these models to execute fraud and other attacks without requiring advanced coding skills. This threat is exacerbated by the availability of tools such as bots-as-a-service, residential proxies, CAPTCHA farms, and more. As a result, it's crucial for individuals and businesses to take proactive measures to protect their online presence. READ FULL STORY

Why Business Social Media Accounts Need Strong Passwords, Too

Corporate Security

Why Business Social Media Accounts Need Strong Passwords, Too

Business leaders and those responsible for their corporate social media accounts can use this reminder about the importance of secure passwords – you’re only one weak password away from a breach. It’s a truth that’s too easily forgotten, especially when it has to do with securing a company’s social media websites. Whether a company’s oversight is internal or done by a third-party provider, breached social media sites start with a compromised password and can end with damage to a company’s brand and worse. READ FULL STORY

Phony Voicemail Links Steal Employee Credentials From Office 365 And Outlook Users

Scams & Phishing

Phony Voicemail Links Steal Employee Credentials From Office 365 And Outlook Users

Most of us know phishing emails and fake texts are a hacker’s calling card for stealing valuable PII. But recently, researchers at Zscaler cloud security sounded the alarm about an unusual malware campaign using voicemail-themed email phishing as the primary hook for cyberattacks. It’s only after Zscaler fell victim to this campaign that the company felt compelled to study it further. Zscaler finds this cybercrime targets employees in the U.S. using Microsoft Office 365 and the Outlook email service. READ FULL STORY

CAPTCHA Used as Bait For Growing Number Of Email Scams

Scams & Phishing

CAPTCHA Used as Bait For Growing Number Of Email Scams

Most of us are familiar with the funky CAPTCHA verification window that occasionally pops-up when signing onto a website. CAPTCHA systems lend a level of credibility to those of us asked to verify online that we’re human and not a bot. Seeing it makes us feel better about the site being more secure than others. After all, only a 100% legitimate website or service would dare use CAPTCHA, right? Wrong. This now Google-owned service has become a favorite bait for scammers who want you to believe they’re legitimate, and it’s working big-time. READ FULL STORY

Top Phishing Scams Continue To Improve And Grow

Education

Top Phishing Scams Continue To Improve And Grow

Much to our dismay, cybercrooks keep finding ways to better the phishing tools they have and find other ways to include new and sneakier methods of thievery. Organizations and individuals are targets and money, identities, credentials, and more are stolen from both every day. Even cyber-savvy users can get caught in phishing scams if they don’t pay close attention to the signs and signals that something isn’t quite right. Reviewing the most pervasive phishing scams is always recommended. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...