Security researchers reported a sharp rise in "paste-and-run" phishing, a social-engineering technique that tricks users into executing attacker-supplied commands by pasting them into Windows tools such as the Run dialog or PowerShell. In these attacks, a lure page covertly places an obfuscated command on the victim's clipboard and presents steps framed as a verification or troubleshooting task, often through a fake CAPTCHA. Red Canary said the method expanded significantly in 2025 and became the second most common initial access vector it observed after traditional phishing, delivering payloads including information stealers, remote management tools, loaders, and cryptominers.
One documented campaign targeted GitHub users with spoofed security alerts claiming critical flaws in their repositories. Victims were sent to github-scanner[.]com, where a fake CAPTCHA instructed them to press Windows+R, Ctrl+V, and Enter, causing PowerShell to run clipboard-pasted malicious code that downloaded l6e.exe; VirusTotal analysis identified the payload as Lumma Stealer, a credential-theft malware. Researchers also warned that variants such as FileFix abuse the Windows File Explorer address bar to run commands, and similar lures have appeared on macOS through fake sites impersonating trusted tools such as Homebrew to distribute Odyssey and Atomic Stealer.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Red Canary documented that the KongTuke activity used both fakeCAPTCHA and FileFix variants during 2025. FileFix abuses the Windows File Explorer address bar to execute attacker-supplied commands as part of the same copy-and-paste social engineering pattern.
Red Canary reported that malicious copy-and-paste, or "paste-and-run," expanded significantly during 2025 and became the second most popular initial access vector after traditional phishing. The technique was used to deliver multiple payload types including information stealers, remote management tools, loaders, and cryptominers.
A phishing campaign sent spoofed GitHub security emails claiming critical vulnerabilities in recipients' repositories and directed victims to github-scanner[.]com. The site used a fake CAPTCHA to trick users into pasting and executing malicious PowerShell commands via Windows Run, which downloaded and launched l6e.exe identified as Lumma Stealer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.