home.social

#lumma — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lumma, aggregated by home.social.

fetched live
  1. #Vercel created & maintains Next.js web development framework. Last month they disclosed a breach via #Lumma stealer #malware infecting an employee's computer. Good #infosec checklist & quick audit from @akeylessio on how to avoid mistakes from @vercel.
    api.cyfluencer.com/s/the-post-

  2. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  3. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  4. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  5. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  6. Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.

    Ahora me explico la caída en picado en la actividad de Lumma.

    #lummastealer #ciberseguridad #cybersecurity

  7. Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.

    Ahora me explico la caída en picado en la actividad de Lumma.

    #lummastealer #ciberseguridad #cybersecurity

  8. 2025-08-13 (Wednesday): #LummaStealer infection. The associated #malware, artifacts, a #pcap of the #Lumma Stealer traffic, and indicators of compromise are available at malware-traffic-analysis.net/2

  9. 2025-08-13 (Wednesday): #LummaStealer infection. The associated #malware, artifacts, a #pcap of the #Lumma Stealer traffic, and indicators of compromise are available at malware-traffic-analysis.net/2

  10. Totgesagte leben länger: Nicht immer sind behördliche Maßnahmen gegen #Cybercrime nachhaltig - so beim Infostealer "#Lumma", der im letzten Jahr durch #Europol abgeschaltet wurde, indem 400.000 infizierte Rechner identifiziert und über Sinkholing aus dem Netz genommen wurden.

    Mittlerweile aber soll der Informationsdiebstahl durch "Lumma" wieder in vollem Gange sein - technische Infrastruktur lässt sich eben doch recht zügig wieder aufbauen, wenn man will:

    heise.de/news/Comeback-von-Lum #cybersecurity

  11. Totgesagte leben länger: Nicht immer sind behördliche Maßnahmen gegen #Cybercrime nachhaltig - so beim Infostealer "#Lumma", der im letzten Jahr durch #Europol abgeschaltet wurde, indem 400.000 infizierte Rechner identifiziert und über Sinkholing aus dem Netz genommen wurden.

    Mittlerweile aber soll der Informationsdiebstahl durch "Lumma" wieder in vollem Gange sein - technische Infrastruktur lässt sich eben doch recht zügig wieder aufbauen, wenn man will:

    heise.de/news/Comeback-von-Lum #cybersecurity

  12. 2025-07-15 (Tuesday): #LummaStealer infection with #SecTopRAT.

    A #pcap of the #Lumma traffic and #SecTop #RAT activity, the #malware/artifacts from an infection, and the associated IOCs are available at malware-traffic-analysis.net/2

  13. 2025-07-02 (Wednesday): Another #LummaStealer infection with follow-up #Rsockstun #malware.

    The #Lumma Stealer infection uses a password-protected 7-zip archive, a NullSoft installer, and #AutoItv3.

    Malware samples, a #pcap and some IOCs are available at malware-traffic-analysis.net/2