# DeceptionAds: Fake CAPTCHA Malvertising Campaign Abusing the Monetag Ad Network to Distribute Lumma Infostealer via ClickFix

> DeceptionAds is a large-scale malvertising operation that abuses the Monetag ad network (and BeMob ad-tracking for cloaking) to serve fraudulent CAPTCHA verification pages. The pages use the ClickFix technique to coerce Windows users into pasting and running an obfuscated PowerShell one-liner that installs the Lumma infostealer. Guardio Labs (with Infoblox) reported over 1 million daily ad impressions across 3,000+ publisher sites and thousands of daily victims.

- **Published:** 2026-06-10T00:00:00Z
- **Last reviewed:** 2026-06-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0769
- **ID:** TL-2026-0769
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Vane Viper
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

DeceptionAds is a single-threat-actor malvertising operation publicly documented by Guardio Labs (Nati Tal) in collaboration with Infoblox on December 16, 2024, and tracked to the actor "Vane Viper" (also previously tracked by Infoblox as Omnatuor). It represents a more dangerous, ad-network-scaled variant of the ClickFix / "CAPTCHAgeddon" social-engineering technique.

The distribution chain begins on high-traffic pirated-content and streaming sites (anime, movies, manga, games, sports streams) that monetize via Monetag, a part of the PropellerAds network. Monetag JavaScript ad tags load obfuscated scripts from Monetag's Traffic Distribution System (TDS). To evade Monetag's content moderation, the actor submitted benign BeMob tracking URLs (leveraging BeMob's reputation) instead of the direct malicious creatives; once approved, the destination was swapped to redirect to fake CAPTCHA pages. The full redirect path is Monetag TDS -> BeMob TDS -> a fake CAPTCHA page hosted on legitimate cloud/CDN object storage (Bunny CDN b-cdn.net subdomains, Oracle Cloud Object Storage, Scaleway, EXOScale, Cloudflare R2, Netlify).

The fake CAPTCHA page imitates Google reCAPTCHA / hCaptcha. When the victim clicks the "I'm not a robot" / verify control, an embedded JavaScript snippet silently writes an obfuscated PowerShell one-liner to the system clipboard. The page then instructs the victim to open the Windows Run dialog (Win+R), paste (Ctrl+V), and press Enter -- the ClickFix "verification steps." Executing the command downloads and runs the Lumma Stealer payload from attacker infrastructure. Lumma harvests browser-stored credentials, cookies/session tokens, password-manager data, cryptocurrency wallets, banking and social-media accounts, and local files, exfiltrating them to C2. Multiple obfuscated PowerShell and JavaScript variants were rotated throughout the campaign to evade Google Safe Browsing and endpoint detection.

Responsibility was fragmented across the abuse chain: the ad network blamed cloaking, the tracking service claimed an analytics-only role, publishers disclaimed the creatives, and hosting providers claimed ignorance. After Guardio's disclosure, Monetag removed 200+ threat-actor accounts (registered with falsified documents) within eight days and BeMob removed cloaking accounts within four days; the campaign briefly paused but Guardio observed a resurgence on December 11, 2024 using Monetag and alternative ad networks, demonstrating actor persistence and platform diversity.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1583.007 Serverless
- T1608.004 Drive-by Target
- T1587.001 Malware
- T1189 Drive-by Compromise
- T1566 Phishing
- T1195 Supply Chain Compromise
- T1204.004 Malicious Copy and Paste
- T1059.001 PowerShell
- T1059.007 JavaScript
- T1027 Obfuscated Files or Information
- T1218.005 Mshta
- T1036 Masquerading
- T1105 Ingress Tool Transfer
- T1071.001 Web Protocols
- T1102 Web Service
- T1555.003 Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1005 Data from Local System
- T1082 System Information Discovery
- T1041 Exfiltration Over C2 Channel

## Sources

- [DeceptionAds: Fake Captcha Driving Infostealer Infections and a Glimpse to the Dark Side of Internet Advertising](https://guard.io/labs/deceptionads-fake-captcha-driving-infostealer-infections-and-a-glimpse-to-the-dark-side-of)
- [DeceptionAds (Guardio Labs, Medium mirror)](https://medium.com/@guardiosecurity/deceptionads-fake-captcha-driving-infostealer-infections-and-a-glimpse-to-the-dark-side-of-0c516f4dc0b6)
- [Malicious ads push Lumma infostealer via fake CAPTCHA pages](https://www.bleepingcomputer.com/news/security/malicious-ads-push-lumma-infostealer-via-fake-captcha-pages/)
- [DeceptionAds Delivers 1M+ Daily Impressions via 3,000 Sites, Fake CAPTCHA Pages](https://thehackernews.com/2024/12/deceptionads-delivers-1m-daily.html)
- [Cross-Examining the CAPTCHAgeddon Brought on by ClickFix](https://circleid.com/posts/cross-examining-the-captchageddon-brought-on-by-clickfix)
- [DeceptionAds (InfoStealers.com mirror)](https://www.infostealers.com/article/deceptionads-fake-captcha-driving-infostealer-infections-and-a-glimpse-to-the-dark-side-of-internet-advertising/)
- [Fake CAPTCHA pages used to spread infostealer malware](https://www.techradar.com/pro/security/fake-captcha-pages-used-to-spread-infostealer-malware)
- [MITRE ATT&CK T1204.004 - User Execution: Malicious Copy and Paste (ClickFix)](https://attack.mitre.org/techniques/T1204/004/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0769
