Threat reportMalwareTL-2026-0769

DeceptionAds: Fake CAPTCHA Malvertising Campaign Abusing the Monetag Ad Network to Distribute Lumma Infostealer via ClickFix

highACTIVE

DeceptionAds (TL-2026-0769), also tracked as DeceptionAds, is a high-severity malware campaign, first published 2026-06-10. It is attributed to Vane Viper with medium confidence, affects Microsoft Windows (endpoints with PowerShell), maps to 21 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
21MITRE ATT&CK
Actors
1Vane Viper
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-0769

Threat ID
TL-2026-0769
Also known as
DeceptionAds, Fake Captcha Campaign, CAPTCHAgeddon, ClickFix
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Vane Viper
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
consumer, media-streaming-audiences, general-public, gaming
Target regions
United States, Europe, Global
Detection rules
9
Indicators of compromise
32

Malware and tooling in DeceptionAds

Malware and tooling: Lumma Stealer - S1213, Monetag TDS -> BeMob TDS redirect chain, mshta.exe

How DeceptionAds works

DeceptionAds is a large-scale malvertising operation that abuses the Monetag ad network (and BeMob ad-tracking for cloaking) to serve fraudulent CAPTCHA verification pages. The pages use the ClickFix technique to coerce Windows users into pasting and running an obfuscated PowerShell one-liner that installs the Lumma infostealer. Guardio Labs (with Infoblox) reported over 1 million daily ad impressions across 3,000+ publisher sites and thousands of daily victims.

DeceptionAds is a single-threat-actor malvertising operation publicly documented by Guardio Labs (Nati Tal) in collaboration with Infoblox on December 16, 2024, and tracked to the actor "Vane Viper" (also previously tracked by Infoblox as Omnatuor). It represents a more dangerous, ad-network-scaled variant of the ClickFix / "CAPTCHAgeddon" social-engineering technique.

The distribution chain begins on high-traffic pirated-content and streaming sites (anime, movies, manga, games, sports streams) that monetize via Monetag, a part of the PropellerAds network. Monetag JavaScript ad tags load obfuscated scripts from Monetag's Traffic Distribution System (TDS). To evade Monetag's content moderation, the actor submitted benign BeMob tracking URLs (leveraging BeMob's reputation) instead of the direct malicious creatives; once approved, the destination was swapped to redirect to fake CAPTCHA pages. The full redirect path is Monetag TDS -> BeMob TDS -> a fake CAPTCHA page hosted on legitimate cloud/CDN object storage (Bunny CDN b-cdn.net subdomains, Oracle Cloud Object Storage, Scaleway, EXOScale, Cloudflare R2, Netlify).

The fake CAPTCHA page imitates Google reCAPTCHA / hCaptcha. When the victim clicks the "I'm not a robot" / verify control, an embedded JavaScript snippet silently writes an obfuscated PowerShell one-liner to the system clipboard. The page then instructs the victim to open the Windows Run dialog (Win+R), paste (Ctrl+V), and press Enter -- the ClickFix "verification steps." Executing the command downloads and runs the Lumma Stealer payload from attacker infrastructure. Lumma harvests browser-stored credentials, cookies/session tokens, password-manager data, cryptocurrency wallets, banking and social-media accounts, and local files, exfiltrating them to C2. Multiple obfuscated PowerShell and JavaScript variants were rotated throughout the campaign to evade Google Safe Browsing and endpoint detection.

Responsibility was fragmented across the abuse chain: the ad network blamed cloaking, the tracking service claimed an analytics-only role, publishers disclaimed the creatives, and hosting providers claimed ignorance. After Guardio's disclosure, Monetag removed 200+ threat-actor accounts (registered with falsified documents) within eight days and BeMob removed cloaking accounts within four days; the campaign briefly paused but Guardio observed a resurgence on December 11, 2024 using Monetag and alternative ad networks, demonstrating actor persistence and platform diversity.

MITRE ATT&CK techniques used in TL-2026-0769

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1218.005 Mshta

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 PowerShell; T1059.007 JavaScript; T1204.004 Malicious Copy and Paste

Command and Control

T1071.001 Web Protocols; T1102 Web Service; T1105 Ingress Tool Transfer

Discovery

T1082 System Information Discovery

Initial Access

T1189 Drive-by Compromise; T1195 Supply Chain Compromise; T1566 Phishing

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Resource Development

T1583 Acquire Infrastructure; T1583.007 Serverless; T1587.001 Malware; T1608.004 Drive-by Target

Affected products and versions in DeceptionAds

  • Microsoft — Windows (endpoints with PowerShell)
    Vulnerable versions: Windows 10; Windows 11
  • Monetag (PropellerAds) — Monetag Ad Network / Traffic Distribution System
    Vulnerable versions: abused as delivery vector
  • BeMob — BeMob Ad Tracking / Cloaking Service
    Vulnerable versions: abused for cloaking

Remediation for DeceptionAds

Immediate actions

  • Block known fake-CAPTCHA hosting subdomains (b-cdn.net, OCI customer-oci.com, exo.io, r2.dev, netlify.app paths) and BeMob cloaking domains at the web proxy/DNS layer
  • Block the listed C2/relay IPs (181.174.164.117, 88.119.175.52, 195.201.221.109) and domains at the perimeter
  • Disable or restrict the Windows Run dialog and clipboard-to-Run workflows via policy where feasible; warn users that no legitimate CAPTCHA ever asks you to press Win+R and paste a command
  • Hunt for recent PowerShell executions launched from explorer.exe/RunMRU with download-and-execute (iwr/iex, mshta) patterns

Workarounds

  • Restrict outbound access so only approved hosts can run script interpreters
  • Use AppLocker/WDAC to constrain script-host execution
  • Reset credentials and browser sessions for any host that executed the pasted command (assume credential theft)

Longer-term hardening

  • Deploy EDR with behavioral detection for clipboard-seeded PowerShell and LOLBins (powershell.exe, mshta.exe) spawned from the Run dialog
  • Enforce PowerShell Constrained Language Mode and script-block + module logging; ship logs to SIEM
  • Roll out user-awareness training specifically on ClickFix / fake-CAPTCHA 'verification steps' social engineering
  • Use DNS filtering / protective DNS to block newly-registered and malvertising-associated domains
  • Deploy reputable ad-blocking / content-filtering on managed endpoints to cut the malvertising delivery vector

Weaknesses (CWE) in DeceptionAds

CWE-451, CWE-1021

Timeline of DeceptionAds

  • Guardio Labs identifies the large-scale fake-CAPTCHA malvertising operation and begins tracking the Monetag-originated redirect chain (approx. initial notification window).
  • BeMob removes the ad-tracking/cloaking accounts used by the threat actor, four days after Guardio's disclosure.
  • Monetag removes 200+ threat-actor accounts (registered with falsified documents), eight days after Guardio's notification.
  • Across a 10-day analysis period in late November 2024, Guardio measures 1M+ daily ad impressions and thousands of daily victims across 3,000+ publisher sites.
  • Guardio observes a resurgence of the campaign using Monetag and alternative ad networks, indicating threat-actor persistence and platform diversity.
  • Guardio Labs (Nati Tal) publishes the DeceptionAds report in collaboration with Infoblox; BleepingComputer and InfoStealers mirror the disclosure the same day.
  • The Hacker News and TechRadar report on DeceptionAds delivering 1M+ daily impressions via 3,000 sites and fake CAPTCHA pages.
  • CircleID / WhoisXML API publish a CAPTCHAgeddon pivot analysis expanding the IOC set (156 domains, 16 IPs in the original set; registrant/IP/string-connected pivots).

Sources cited for DeceptionAds

Detection coverage for TL-2026-0769

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0769 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats