Since late 2024, a sophisticated phishing operation leveraging 260 domains to host over 5,000 weaponized PDF files has targeted users across North America, Asia, and Southern Europe.
The campaign employs fake CAPTCHA screens, search engine optimization (SEO) poisoning, and PowerShell-based payload delivery to steal credit card data and deploy the Lumma Stealer malware.
The attacks have impacted 1,150 organizations and 7,000 individuals, with technology, financial services, and manufacturing sectors being the most affected.
Fake CAPTCHAs and Obfuscated PowerShell Payloads
Discovered by Netskope Threat Labs, the campaign begins when victims search for documents like user manuals, templates, or forms on search engines.
Attackers exploit SEO tactics to push malicious PDFs—hosted on compromised content delivery networks (CDNs) such as Webflow, GoDaddy’s wsimg.com, and Strikingly—to the top of search results.
These PDFs embed fake CAPTCHA verification screens that redirect users to phishing pages. Unlike legitimate CAPTCHAs, these images contain hyperlinks masked as validation checks, routing victims to credential-harvesting sites or triggering malware downloads.
In a subset of attacks, clicking the CAPTCHA copies obfuscated PowerShell code to the victim’s clipboard. When executed, this code invokes mshta, a legitimate Windows utility, to fetch a malicious script from domains like get-verified.b-cdn[.]net.
The script then downloads Lumma Stealer, an information-stealing malware-as-a-service (MaaS) tool that exfiltrates passwords, session tokens, and cryptocurrency wallets.
Notably, attackers force the use of PowerShell v1.0 to bypass modern security protocols.
“The MSHTA command downloads the next stage PowerShell script, which downloads and executes the Lumma Stealer malware”, researchers said.
The malware employs Process Hollowing to inject malicious code into legitimate executables, evading endpoint detection. It then exfiltrates data via HTTPS to C2 servers hosted on Fastly and Wix infrastructure.
Cross-Platform Exploitation
The campaign’s infrastructure spans 260 domains, including PDF repositories like PDFCoffee and Internet Archive, broadening its reach to users searching within document libraries.
Over 4,000 keywords including “free download,” “printable,” and “template” were targeted to optimize malicious PDF visibility.
Webflow’s CDN (assets.website-files[.]com) emerged as the primary host, accounting for 42% of phishing PDFs, followed by GoDaddy-associated subdomains.
Geographically, 58% of victims were in North America, with 27% in Asia and 15% in Southern Europe. Sector-specific targeting prioritized technology firms (34%), financial institutions (28%), and manufacturing entities (19%), likely due to their access to proprietary data and payment systems.
Mitigation
Organizations are advised to:
- Disable legacy PowerShell versions to prevent downgrade attacks.
- Monitor CDN traffic for anomalous connections to Webflow or GoDaddy subdomains.
- Implement application allowlisting to restrict unauthorized script execution.
By weaponizing SEO, CDNs, and legacy tools, threat actors amplify their reach while complicating attribution.
As phishing tactics grow more sophisticated, proactive threat hunting and cross-industry collaboration remain critical to disrupting the cybercrime lifecycle.
Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free
