Campaign record
Emmenhtal Loader inside an MP3
Emmenhtal loader delivered as a booby-trapped MP3 and followed by Lumma Stealer
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- 2025-05-19
- Indicators
- 11
- Sources
- 1
- Targets
- Windows
- Fake CAPTCHA verification
- Emmenhtal Loader
- Lumma Stealer
Original research
- Trend Micro2025-05-19Vendor researchFirst account
Fake CAPTCHA Attacks Deploy Infostealers and RATs in a Multistage Payload Chain
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Trend Micro's managed detection team traced a delivery chain that opens with a counterfeit human-verification page. The visitor is told to paste an mshta command, which fetches what looks like an ordinary audio track. The track really does play music, but it also carries JavaScript wrapped first in base64 and then in hexadecimal, which Trend Micro attributes to the Emmenhtal loader. Unwrapping it starts a hidden PowerShell process that pulls down a second script disguised with a spreadsheet extension, injects code into svchost.exe and reaches a command server on port 8587. Lumma Stealer follows, together with DLL sideloading from a browser-updater executable dropped into a user profile directory, and a browser launched on a throwaway profile against a local listener. Several of the audio files were sourced from a royalty-free music library and modified.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| PowerShell | 19 of 4443% | T1059.001 |
| mshta.exe | 7 of 4416% | T1218.005 |
Both of these mechanisms appear together in 4 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
11 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Emmenhtal Loader inside an MP3”, campaign ID deeaf6a4, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/deeaf6a4/emmenhtal-mp3-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.