home.social

#lumma — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lumma, aggregated by home.social.

fetched live
  1. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  2. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  3. Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.

    Ahora me explico la caída en picado en la actividad de Lumma.

    #lummastealer #ciberseguridad #cybersecurity

  4. 2025-08-13 (Wednesday): #LummaStealer infection. The associated #malware, artifacts, a #pcap of the #Lumma Stealer traffic, and indicators of compromise are available at malware-traffic-analysis.net/2

  5. Totgesagte leben länger: Nicht immer sind behördliche Maßnahmen gegen #Cybercrime nachhaltig - so beim Infostealer "#Lumma", der im letzten Jahr durch #Europol abgeschaltet wurde, indem 400.000 infizierte Rechner identifiziert und über Sinkholing aus dem Netz genommen wurden.

    Mittlerweile aber soll der Informationsdiebstahl durch "Lumma" wieder in vollem Gange sein - technische Infrastruktur lässt sich eben doch recht zügig wieder aufbauen, wenn man will:

    heise.de/news/Comeback-von-Lum #cybersecurity