Lure theme
Download gate verification
A verification step wedged between a visitor and a file they were already trying to get: cracked software, a game modification, a media file, a driver. The audience arrives motivated and slightly furtive, which is a poor state in which to question an odd instruction. Unlike most themes, this one is usually reached through SEO poisoning and paid ads rather than through a compromised legitimate site.
- First reported
- 2024-10
- Targets
- Windows · macOS
- Campaigns on record
- 5
Approximate. Download-gate variants track the wider fake-CAPTCHA wave from late 2024.
Also reported as Verify before download · Anti-bot download check · Fake file-host verification · Download unlock lure
What a victim sees
A download page in the style of a file host or software mirror, with a file name, a size and a progress element, followed by a gate: confirm you are human, confirm you are not using a download manager, unlock the file. Clearing the gate produces keyboard steps. Some builds add a comment thread underneath in which earlier visitors report that the steps worked and thank the uploader — the one part of the page written to be read closely.
Described rather than shown. This site publishes no screenshots of lure pages and reproduces none of their markup, because a working copy of a fake verification page is a fake verification page regardless of why it was made.
The tell-tale sign
No file host needs the Run dialog or Terminal to release a download. If a download requires a command, the command is the download.
The underlying rule is the same for every theme on this site, and it is the one worth remembering: no legitimate website will ever ask you to press Windows+R, to open Terminal, or to paste anything into either one. Why that rule holds.
Campaigns using this lure
SHub and MacSync via GitHub lures
Status as last assessed: ActiveDatadog Security Labs described this operation on 10 February 2026 and assessed it as ongoing. GitHub repositories posing as desktop software from technology firms — one advertised a Datadog desktop application that does not exist — held only a README whose download link began a redirect chain. A GitHub Pages site styled after GitHub itself profiled each visitor, posted the fingerprint to a Google Apps Script address, and sorted traffic: macOS visitors reached a ClickFix page, Windows a ZIP download, others a genuine pricing page. The ClickFix page had the visitor paste a Terminal command that pulled a shell script and executed it. Earlier variants installed MacSync, formerly Mac.c, which swapped resources of installed wallet applications; later ones delivered SHub Stealer v2.0, which validates the phished password, gathers documents, browser and wallet data, and persists as a counterfeit Google updater beaconing for commands. Datadog reported the repositories to GitHub.
ID 3c150b60First seen —Last seen —macOSPhantom Meet fake download sites
Status as last assessed: ActiveSekoia grouped a large set of counterfeit download sites with the fake Google Meet pages it was tracking, on registration records, passive DNS, and page construction that repeats across the estate. The brands are borrowed or invented outright: video conferencing, document utilities, several games that do not exist, Web3 browsers and messengers, a metaverse client. Every page runs the same script — the visitor is told a check has failed, then walked through pasting a command. Windows visitors were sent Stealc or Rhadamanthys; macOS visitors were sent AMOS. Distribution ran through affiliate crews rather than one operator, which is why the naming conventions wander while the page templates do not. We hold this as a single estate because that is how the source groups it; the individual lure themes are tagged separately below.
ID 8562b3edFirst seen —Last seen —Windows · macOSKimsuky deploying QuasarRAT
Status as last assessed: ActiveProofpoint ties this chain to TA427, the North Korean group others track as Kimsuky and Emerald Sleet. Operators approached staff at a handful of think tanks working on North Korean affairs with a spoofed meeting invitation, built rapport, then sent a PDF whose link pointed at a dynamic-DNS host dressed up as a corporate file store. Trying to open the decoy document raised a registration pop-up that handed the reader a licence-style code hiding a PowerShell instruction to paste into a terminal. Running it fetched a second script, showed a Japanese foreign-ministry questionnaire as cover, and set scheduled tasks that ran a VBS stager every nineteen minutes. One January 2025 instance went further: batch files decoded a Base64 and XOR-wrapped QuasarRAT that reached its controller over port 80. Delivery names sat on FreeDNS and No-IP services, largely on hacked South Korean servers.
ID 71f11de9First seen 2025-01-01Last seen 2025-04-01WindowsAMOS behind a fingerprint gate
Status as last assessed: ActiveMicrosoft Threat Intelligence tracked a cluster of more than 250 look-alike download domains distributing macOS information stealers, among them MacSync and Atomic Stealer. Many names come from a generator pairing the token "file" with two dictionary words, across .com, .sbs and .online, though some place it elsewhere or omit it. Early pages handed the paste-into-Terminal instruction to any visitor; the operators later put a small JavaScript profiler in front, reading navigator, screen and WebGL values, timezone, iframe and touch state, plus tripwires for an open developer console and hooked prototypes, then posting the result back for a server-side ruling. Requests that fail receive a blank shell, a bogus VPN-extension page or an unrelated business site, so a benign answer proves little. Those that pass see a forged Verified Publisher badge, spoofed GitHub styling and a one-click Terminal command ending in Atomic Stealer.
ID ee88ee33First seen —Last seen —macOSOBSCURE#BAT via a Discord lure
Status as last assessed: ActiveOBSCURE#BAT is the name Securonix gave to activity that installs an altered build of r77, an open-source rootkit whose value to an operator is staying hidden and staying put. Microsoft attributes one of the lure pages it pulls apart in this write-up to that same cluster. The page presents itself as a Discord server that wants a visitor identified before letting them join, and borrows the platform's own logo to sell the idea. Its script waits for the verify button and then uses the browser's clipboard interface to load a command, with no hidden frame and no message from another document involved — plainer than the other example Microsoft dissects, where a concealed frame signals the parent page. Recorded alongside it are a landing page, a batch file on a public file host, and two addresses used for control between February and March 2025.
ID 092c751dFirst seen 2025-02-24Last seen 2025-03-27Windows