Counterfeit CAPTCHA PDFs Disseminate Lumma Stealer through Webflow, GoDaddy, and Alternative Domains
Security analysts have revealed an extensive phishing scheme that employs forged CAPTCHA visuals distributed via PDF files hosted on Webflow’s content delivery network (CDN) to disperse the Lumma stealer malware. Netskope Threat Labs reported identifying 260 distinct domains carrying 5,000 phishing PDFs that reroute targets to malevolent websites. “The offensive party leverages SEO tactics to deceive targets into
