#lumma — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #lumma, aggregated by home.social.
-
#Vercel created & maintains Next.js web development framework. Last month they disclosed a breach via #Lumma stealer #malware infecting an employee's computer. Good #infosec checklist & quick audit from @akeylessio on how to avoid mistakes from @vercel.
https://api.cyfluencer.com/s/the-post-vercel-secrets-checklist-a-30-minute-audit-for-your-stack-27237 -
2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.
A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at https://www.malware-traffic-analysis.net/2026/01/01/index.html
Lumma Stealer C2 domain: offenms[.]cyou
The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc
-
2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.
A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at https://www.malware-traffic-analysis.net/2026/01/01/index.html
Lumma Stealer C2 domain: offenms[.]cyou
The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc
-
2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.
A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html
I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.
Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.
If anyone knows what the follow-up malware is, please share that info!
-
2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.
A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html
I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.
Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.
If anyone knows what the follow-up malware is, please share that info!
-
Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.
Ahora me explico la caída en picado en la actividad de Lumma.
-
Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.
Ahora me explico la caída en picado en la actividad de Lumma.
-
Rede ‘Fantasma’ no YouTube: Milhares de vídeos com malware removidos pela Google
🔗 https://tugatech.com.pt/t73321-rede-fantasma-no-youtube-milhares-de-videos-com-malware-removidos-pela-google#Adobe #criptomoedas #Github #google #Lumma #malware #phishing #Photoshop #Roblox #segurança #servidores #software #tutoriais #youtube
-
Rede ‘Fantasma’ no YouTube: Milhares de vídeos com malware removidos pela Google
🔗 https://tugatech.com.pt/t73321-rede-fantasma-no-youtube-milhares-de-videos-com-malware-removidos-pela-google#Adobe #criptomoedas #Github #google #Lumma #malware #phishing #Photoshop #Roblox #segurança #servidores #software #tutoriais #youtube
-
Vidar Stealer 2.0 Boosts Infostealer’s Credential Theft and Evasion Capabilities https://thecyberexpress.com/vidar-stealer-2-0-infostealer/ #TheCyberExpressNews #ThreatIntelligence #CredentialAttacks #LummaInfostealer #VidarInfostealer #TheCyberExpress #FirewallDaily #infostealer #cybercrime #CyberNews #Lumma #Vidar
-
Vidar Stealer 2.0 Boosts Infostealer’s Credential Theft and Evasion Capabilities https://thecyberexpress.com/vidar-stealer-2-0-infostealer/ #TheCyberExpressNews #ThreatIntelligence #CredentialAttacks #LummaInfostealer #VidarInfostealer #TheCyberExpress #FirewallDaily #infostealer #cybercrime #CyberNews #Lumma #Vidar
-
RE: https://infosec.exchange/@patrickcmiller/115414802165768074
For those interested in the doxxing published on website named ‘Lumma Rats, here's the site:
lummakrysy[.]rip
-
RE: https://infosec.exchange/@patrickcmiller/115414802165768074
For those interested in the doxxing published on website named ‘Lumma Rats, here's the site:
lummakrysy[.]rip
-
Hackers usam blockchain para distribuir malware que rouba dados em Windows e macOS
🔗 https://tugatech.com.pt/t73114-hackers-usam-blockchain-para-distribuir-malware-que-rouba-dados-em-windows-e-macos#armazenamento #ataque #blockchain #browser #detetado #engenhariasocial #google #hackers #javascript #Lumma #macos #malware #payload #proxy #sem #servidor #software #windows #WordPress
-
Hackers usam blockchain para distribuir malware que rouba dados em Windows e macOS
🔗 https://tugatech.com.pt/t73114-hackers-usam-blockchain-para-distribuir-malware-que-rouba-dados-em-windows-e-macos#armazenamento #ataque #blockchain #browser #detetado #engenhariasocial #google #hackers #javascript #Lumma #macos #malware #payload #proxy #sem #servidor #software #windows #WordPress
-
Mapping latest Lumma infrastructure
#Lumma
https://intelinsights.substack.com/p/mapping-latest-lumma-infrastructure -
Mapping latest Lumma infrastructure
#Lumma
https://intelinsights.substack.com/p/mapping-latest-lumma-infrastructure -
Behind the Curtain: How Lumma Affiliates Operate
#Lumma #GhostSocks #AnonRDP #BulletproofHosting #HostCay #OnlineSIM #SMS_Activate #Zadarma
https://www.recordedfuture.com/research/behind-the-curtain-how-lumma-affiliates-operate -
Behind the Curtain: How Lumma Affiliates Operate
#Lumma #GhostSocks #AnonRDP #BulletproofHosting #HostCay #OnlineSIM #SMS_Activate #Zadarma
https://www.recordedfuture.com/research/behind-the-curtain-how-lumma-affiliates-operate -
Scammers Compromised by Own Malware, Expose $4.67M Operation https://hackread.com/scammers-compromised-by-malware-expose-operation/ #Cybersecurity #Infostealer #CyberCrime #CloudSEK #Pakistan #Malware #Privacy #Piracy #Lumma #AMOS #Scam
-
Scammers Compromised by Own Malware, Expose $4.67M Operation https://hackread.com/scammers-compromised-by-malware-expose-operation/ #Cybersecurity #Infostealer #CyberCrime #CloudSEK #Pakistan #Malware #Privacy #Piracy #Lumma #AMOS #Scam
-
Scammers Compromised by Own Malware, Expose $4.67M Operation – Source:hackread.com https://ciso2ciso.com/scammers-compromised-by-own-malware-expose-4-67m-operation-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Infostealer #CyberCrime #CloudSEK #Hackread #Pakistan #malware #privacy #Piracy #Lumma #AMOS #Scam
-
Scammers Compromised by Own Malware, Expose $4.67M Operation – Source:hackread.com https://ciso2ciso.com/scammers-compromised-by-own-malware-expose-4-67m-operation-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Infostealer #CyberCrime #CloudSEK #Hackread #Pakistan #malware #privacy #Piracy #Lumma #AMOS #Scam
-
2025-08-13 (Wednesday): #LummaStealer infection. The associated #malware, artifacts, a #pcap of the #Lumma Stealer traffic, and indicators of compromise are available at https://www.malware-traffic-analysis.net/2025/08/13/index.html
-
2025-08-13 (Wednesday): #LummaStealer infection. The associated #malware, artifacts, a #pcap of the #Lumma Stealer traffic, and indicators of compromise are available at https://www.malware-traffic-analysis.net/2025/08/13/index.html
-
Comeback von #Lumma und NoName057(16): #Cybercrime-Zerschlagung misslungen | Security https://www.heise.de/news/Comeback-von-Lumma-und-NoName057-16-Cybercrime-Zerschlagung-misslungen-10498191.html #Malware #Ransomware #NoName05716
-
Comeback von #Lumma und NoName057(16): #Cybercrime-Zerschlagung misslungen | Security https://www.heise.de/news/Comeback-von-Lumma-und-NoName057-16-Cybercrime-Zerschlagung-misslungen-10498191.html #Malware #Ransomware #NoName05716
-
Totgesagte leben länger: Nicht immer sind behördliche Maßnahmen gegen #Cybercrime nachhaltig - so beim Infostealer "#Lumma", der im letzten Jahr durch #Europol abgeschaltet wurde, indem 400.000 infizierte Rechner identifiziert und über Sinkholing aus dem Netz genommen wurden.
Mittlerweile aber soll der Informationsdiebstahl durch "Lumma" wieder in vollem Gange sein - technische Infrastruktur lässt sich eben doch recht zügig wieder aufbauen, wenn man will:
https://www.heise.de/news/Comeback-von-Lumma-und-NoName057-16-Cybercrime-Zerschlagung-misslungen-10498191.html #cybersecurity
-
Totgesagte leben länger: Nicht immer sind behördliche Maßnahmen gegen #Cybercrime nachhaltig - so beim Infostealer "#Lumma", der im letzten Jahr durch #Europol abgeschaltet wurde, indem 400.000 infizierte Rechner identifiziert und über Sinkholing aus dem Netz genommen wurden.
Mittlerweile aber soll der Informationsdiebstahl durch "Lumma" wieder in vollem Gange sein - technische Infrastruktur lässt sich eben doch recht zügig wieder aufbauen, wenn man will:
https://www.heise.de/news/Comeback-von-Lumma-und-NoName057-16-Cybercrime-Zerschlagung-misslungen-10498191.html #cybersecurity
-
Lumma Stealer Is Back & Stealthier Than Ever – Source: www.darkreading.com https://ciso2ciso.com/lumma-stealer-is-back-stealthier-than-ever-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #DARKReading #Lumma
-
Lumma Stealer Is Back & Stealthier Than Ever – Source: www.darkreading.com https://ciso2ciso.com/lumma-stealer-is-back-stealthier-than-ever-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #DARKReading #Lumma
-
GitHub Abused to Spread Amadey, Lumma and Redline InfoStealers in Ukraine – Source:hackread.com https://ciso2ciso.com/github-abused-to-spread-amadey-lumma-and-redline-infostealers-in-ukraine-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #CyberAttacks #CyberAttack #SmokeLoader #Emmenhtal #AsyncRAT #Hackread #security #malware #Redline #Ukraine #Amadey #GitHub #Python #Lumma
-
GitHub Abused to Spread Amadey, Lumma and Redline InfoStealers in Ukraine – Source:hackread.com https://ciso2ciso.com/github-abused-to-spread-amadey-lumma-and-redline-infostealers-in-ukraine-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #CyberAttacks #CyberAttack #SmokeLoader #Emmenhtal #AsyncRAT #Hackread #security #malware #Redline #Ukraine #Amadey #GitHub #Python #Lumma
-
GitHub Abused to Spread Amadey, Lumma and Redline InfoStealers in Ukraine https://hackread.com/github-abused-amadey-lumma-redline-infostealers-ukraine/ #Cybersecurity #CyberAttacks #CyberAttack #SmokeLoader #Emmenhtal #Security #AsyncRAT #Malware #Redline #Ukraine #Amadey #GitHub #Python #Lumma
-
GitHub Abused to Spread Amadey, Lumma and Redline InfoStealers in Ukraine https://hackread.com/github-abused-amadey-lumma-redline-infostealers-ukraine/ #Cybersecurity #CyberAttacks #CyberAttack #SmokeLoader #Emmenhtal #Security #AsyncRAT #Malware #Redline #Ukraine #Amadey #GitHub #Python #Lumma
-
2025-07-15 (Tuesday): #LummaStealer infection with #SecTopRAT.
A #pcap of the #Lumma traffic and #SecTop #RAT activity, the #malware/artifacts from an infection, and the associated IOCs are available at https://www.malware-traffic-analysis.net/2025/07/15/index.html
-
Leaked Shellter Elite Tool Now Fueling Infostealer Attacks Worldwide https://hackread.com/leaked-shellter-elite-tool-infostealer-attacks-worldwide/ #Cybersecurity #ShellterElite #CyberAttacks #ArechClient2 #Rhadamanthys #CyberAttack #Infostealer #CyberCrime #Security #security #Lumma
-
Leaked Shellter Elite Tool Now Fueling Infostealer Attacks Worldwide – Source:hackread.com https://ciso2ciso.com/leaked-shellter-elite-tool-now-fueling-infostealer-attacks-worldwide-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #ShellterElite #ArechClient2 #CyberAttacks #Rhadamanthys #CyberAttack #Infostealer #CyberCrime #Hackread #security #Lumma
-
2025-07-02 (Wednesday): Another #LummaStealer infection with follow-up #Rsockstun #malware.
The #Lumma Stealer infection uses a password-protected 7-zip archive, a NullSoft installer, and #AutoItv3.
Malware samples, a #pcap and some IOCs are available at https://www.malware-traffic-analysis.net/2025/07/02/index.html