Threat reportMalwareTL-2026-0769
DeceptionAds: Fake CAPTCHA Malvertising Campaign Abusing the Monetag Ad Network to Distribute Lumma Infostealer via ClickFix
DeceptionAds (TL-2026-0769), also tracked as DeceptionAds, is a high-severity malware campaign, first published 2026-06-10. It is attributed to Vane Viper with medium confidence, affects Microsoft Windows (endpoints with PowerShell), maps to 21 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 1Vane Viper
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-0769
- Threat ID
- TL-2026-0769
- Also known as
- DeceptionAds, Fake Captcha Campaign, CAPTCHAgeddon, ClickFix
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Vane Viper
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- consumer, media-streaming-audiences, general-public, gaming
- Target regions
- United States, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in DeceptionAds
Malware and tooling: Lumma Stealer - S1213, Monetag TDS -> BeMob TDS redirect chain, mshta.exe
How DeceptionAds works
DeceptionAds is a large-scale malvertising operation that abuses the Monetag ad network (and BeMob ad-tracking for cloaking) to serve fraudulent CAPTCHA verification pages. The pages use the ClickFix technique to coerce Windows users into pasting and running an obfuscated PowerShell one-liner that installs the Lumma infostealer. Guardio Labs (with Infoblox) reported over 1 million daily ad impressions across 3,000+ publisher sites and thousands of daily victims.
DeceptionAds is a single-threat-actor malvertising operation publicly documented by Guardio Labs (Nati Tal) in collaboration with Infoblox on December 16, 2024, and tracked to the actor "Vane Viper" (also previously tracked by Infoblox as Omnatuor). It represents a more dangerous, ad-network-scaled variant of the ClickFix / "CAPTCHAgeddon" social-engineering technique.
The distribution chain begins on high-traffic pirated-content and streaming sites (anime, movies, manga, games, sports streams) that monetize via Monetag, a part of the PropellerAds network. Monetag JavaScript ad tags load obfuscated scripts from Monetag's Traffic Distribution System (TDS). To evade Monetag's content moderation, the actor submitted benign BeMob tracking URLs (leveraging BeMob's reputation) instead of the direct malicious creatives; once approved, the destination was swapped to redirect to fake CAPTCHA pages. The full redirect path is Monetag TDS -> BeMob TDS -> a fake CAPTCHA page hosted on legitimate cloud/CDN object storage (Bunny CDN b-cdn.net subdomains, Oracle Cloud Object Storage, Scaleway, EXOScale, Cloudflare R2, Netlify).
The fake CAPTCHA page imitates Google reCAPTCHA / hCaptcha. When the victim clicks the "I'm not a robot" / verify control, an embedded JavaScript snippet silently writes an obfuscated PowerShell one-liner to the system clipboard. The page then instructs the victim to open the Windows Run dialog (Win+R), paste (Ctrl+V), and press Enter -- the ClickFix "verification steps." Executing the command downloads and runs the Lumma Stealer payload from attacker infrastructure. Lumma harvests browser-stored credentials, cookies/session tokens, password-manager data, cryptocurrency wallets, banking and social-media accounts, and local files, exfiltrating them to C2. Multiple obfuscated PowerShell and JavaScript variants were rotated throughout the campaign to evade Google Safe Browsing and endpoint detection.
Responsibility was fragmented across the abuse chain: the ad network blamed cloaking, the tracking service claimed an analytics-only role, publishers disclaimed the creatives, and hosting providers claimed ignorance. After Guardio's disclosure, Monetag removed 200+ threat-actor accounts (registered with falsified documents) within eight days and BeMob removed cloaking accounts within four days; the campaign briefly paused but Guardio observed a resurgence on December 11, 2024 using Monetag and alternative ad networks, demonstrating actor persistence and platform diversity.
MITRE ATT&CK techniques used in TL-2026-0769
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1218.005 Mshta
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.001 PowerShell; T1059.007 JavaScript; T1204.004 Malicious Copy and Paste
Command and Control
T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery
Initial Access
T1189 Drive-by Compromise; T1195 Supply Chain Compromise; T1566 Phishing
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Resource Development
T1583 Acquire Infrastructure; T1583.007 Serverless; T1587.001 Malware; T1608.004 Drive-by Target
Affected products and versions in DeceptionAds
- Microsoft — Windows (endpoints with PowerShell)
Vulnerable versions: Windows 10; Windows 11 - Monetag (PropellerAds) — Monetag Ad Network / Traffic Distribution System
Vulnerable versions: abused as delivery vector - BeMob — BeMob Ad Tracking / Cloaking Service
Vulnerable versions: abused for cloaking
Remediation for DeceptionAds
Immediate actions
- Block known fake-CAPTCHA hosting subdomains (b-cdn.net, OCI customer-oci.com, exo.io, r2.dev, netlify.app paths) and BeMob cloaking domains at the web proxy/DNS layer
- Block the listed C2/relay IPs (181.174.164.117, 88.119.175.52, 195.201.221.109) and domains at the perimeter
- Disable or restrict the Windows Run dialog and clipboard-to-Run workflows via policy where feasible; warn users that no legitimate CAPTCHA ever asks you to press Win+R and paste a command
- Hunt for recent PowerShell executions launched from explorer.exe/RunMRU with download-and-execute (iwr/iex, mshta) patterns
Workarounds
- Restrict outbound access so only approved hosts can run script interpreters
- Use AppLocker/WDAC to constrain script-host execution
- Reset credentials and browser sessions for any host that executed the pasted command (assume credential theft)
Longer-term hardening
- Deploy EDR with behavioral detection for clipboard-seeded PowerShell and LOLBins (powershell.exe, mshta.exe) spawned from the Run dialog
- Enforce PowerShell Constrained Language Mode and script-block + module logging; ship logs to SIEM
- Roll out user-awareness training specifically on ClickFix / fake-CAPTCHA 'verification steps' social engineering
- Use DNS filtering / protective DNS to block newly-registered and malvertising-associated domains
- Deploy reputable ad-blocking / content-filtering on managed endpoints to cut the malvertising delivery vector
Weaknesses (CWE) in DeceptionAds
Timeline of DeceptionAds
- Guardio Labs identifies the large-scale fake-CAPTCHA malvertising operation and begins tracking the Monetag-originated redirect chain (approx. initial notification window).
- BeMob removes the ad-tracking/cloaking accounts used by the threat actor, four days after Guardio's disclosure.
- Monetag removes 200+ threat-actor accounts (registered with falsified documents), eight days after Guardio's notification.
- Across a 10-day analysis period in late November 2024, Guardio measures 1M+ daily ad impressions and thousands of daily victims across 3,000+ publisher sites.
- Guardio observes a resurgence of the campaign using Monetag and alternative ad networks, indicating threat-actor persistence and platform diversity.
- Guardio Labs (Nati Tal) publishes the DeceptionAds report in collaboration with Infoblox; BleepingComputer and InfoStealers mirror the disclosure the same day.
- The Hacker News and TechRadar report on DeceptionAds delivering 1M+ daily impressions via 3,000 sites and fake CAPTCHA pages.
- CircleID / WhoisXML API publish a CAPTCHAgeddon pivot analysis expanding the IOC set (156 domains, 16 IPs in the original set; registrant/IP/string-connected pivots).
Sources cited for DeceptionAds
- DeceptionAds: Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising
- DeceptionAds (Guardio Labs, Medium mirror)
- Malicious ads push Lumma infostealer via fake CAPTCHA pages
- DeceptionAds Delivers 1M+ Daily Impressions via 3,000 Sites, Fake CAPTCHA Pages
- Cross-Examining the CAPTCHAgeddon Brought on by ClickFix
- DeceptionAds (InfoStealers.com mirror)
- Fake CAPTCHA pages used to spread infostealer malware
- MITRE ATT&CK T1204.004 - User Execution: Malicious Copy and Paste (ClickFix)
Detection coverage for TL-2026-0769
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0769 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.