Kaspersky’s telemetry recorded over 140,000 encounters with these malicious ads in September and October 2024, and more than 20,000 users were redirected to the fake pages hosting malicious scripts. This threat was encountered by users in many regions, including LATAM, Africa, the Middle East, and Asia. To stay safe, experts advise users to exercise caution and avoid following suspicious prompts for action online.
A CAPTCHA is a security feature used on websites and in apps to verify whether a user is human or an automated program or bot. Earlier this year, there were reports of attackers distributing the Lumma stealer using fake CAPTCHAs, primarily targeting gamers. When browsing gaming websites, users were lured into clicking on an ad that covered the entire screen.
They were redirected to a fake CAPTCHA page with instructions below the prompt tricking them into downloading the stealer. When users clicked the I'm not a robot button, an encoded Windows PowerShell command was copied to their PC’s clipboard. They were then prompted to paste it into the terminal box and press Enter, inadvertently downloading and launching Lumma.
The malware searched for cryptocurrency-related files, cookies, and password manager data on the victim's device. It also visited the webpages of various e-commerce platforms, boosting their view counts, giving the attackers additional financial gain.
![]() |
| A fake CAPTCHA with malicious instructions |
![]() |
| A fake message mimicking Google Chrome |
Read more on Securelist.
To block threats related to stealers, follow the recommendations below.
Businesses:
- Check if the credentials for your company’s devices or web applications have been compromised by stealers on the dedicated Kaspersky Digital Footprint Intelligence landing page
- Use a dedicated security solution such as Kaspersky Endpoint Security for Business with application and web control; behaviour analysis helps quickly detect malicious activity
- Look into boosting your employees’ digital literacy to minimise the cyber risks from the human side by using an online tool that offers comprehensive cyber trainings for staff
Individuals:
- Use a comprehensive security solution, such as award-winning Kaspersky Premium, on all of your devices, to prevent opening suspicious pages or phishing emails
- Use Kaspersky Password Manager to store your passwords securely


