home.social

#lumma — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lumma, aggregated by home.social.

fetched live
  1. 📢 La montée des infostealers open source menace de déclencher une nouvelle vague d'infections
    📝 📰 **Source** : infostealers.com (Hudson Rock) — **Date** : 1er juillet 2024

    L'ar...
    📖 cyberveille : cyberveille.ch/posts/2026-06-2
    🌐 source : infostealers.com/article/open-
    #Lumma #Poseidon #Cyberveille

  2. 📢 Les infostealers redéfinissent la surface d'attaque : 11,1 millions d'appareils compromis en 2025
    📝 ## 🌐 Contexte

    Publié le 10 juin 2026 par Flashpoint sur son blog officiel, cet article accompagne la sortie d'un guid...
    📖 cyberveille : cyberveille.ch/posts/2026-06-1
    🌐 source : flashpoint.io/blog/proactive-d
    #Acreed #Lumma #Cyberveille

  3. #Vercel created & maintains Next.js web development framework. Last month they disclosed a breach via #Lumma stealer #malware infecting an employee's computer. Good #infosec checklist & quick audit from @akeylessio on how to avoid mistakes from @vercel.
    api.cyfluencer.com/s/the-post-

  4. #Vercel created & maintains Next.js web development framework. Last month they disclosed a breach via #Lumma stealer #malware infecting an employee's computer. Good #infosec checklist & quick audit from @akeylessio on how to avoid mistakes from @vercel.
    api.cyfluencer.com/s/the-post-

  5. #Vercel created & maintains Next.js web development framework. Last month they disclosed a breach via #Lumma stealer #malware infecting an employee's computer. Good #infosec checklist & quick audit from @akeylessio on how to avoid mistakes from @vercel.
    api.cyfluencer.com/s/the-post-

  6. #Vercel created & maintains Next.js web development framework. Last month they disclosed a breach via #Lumma stealer #malware infecting an employee's computer. Good #infosec checklist & quick audit from @akeylessio on how to avoid mistakes from @vercel.
    api.cyfluencer.com/s/the-post-

  7. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  8. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  9. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  10. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  11. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  12. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  13. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  14. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  15. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  16. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  17. Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.

    Ahora me explico la caída en picado en la actividad de Lumma.

    #lummastealer #ciberseguridad #cybersecurity

  18. Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.

    Ahora me explico la caída en picado en la actividad de Lumma.

    #lummastealer #ciberseguridad #cybersecurity

  19. Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.

    Ahora me explico la caída en picado en la actividad de Lumma.

    #lummastealer #ciberseguridad #cybersecurity

  20. 2025-08-13 (Wednesday): #LummaStealer infection. The associated #malware, artifacts, a #pcap of the #Lumma Stealer traffic, and indicators of compromise are available at malware-traffic-analysis.net/2

  21. 2025-08-13 (Wednesday): #LummaStealer infection. The associated #malware, artifacts, a #pcap of the #Lumma Stealer traffic, and indicators of compromise are available at malware-traffic-analysis.net/2

  22. Totgesagte leben länger: Nicht immer sind behördliche Maßnahmen gegen #Cybercrime nachhaltig - so beim Infostealer "#Lumma", der im letzten Jahr durch #Europol abgeschaltet wurde, indem 400.000 infizierte Rechner identifiziert und über Sinkholing aus dem Netz genommen wurden.

    Mittlerweile aber soll der Informationsdiebstahl durch "Lumma" wieder in vollem Gange sein - technische Infrastruktur lässt sich eben doch recht zügig wieder aufbauen, wenn man will:

    heise.de/news/Comeback-von-Lum #cybersecurity

  23. Totgesagte leben länger: Nicht immer sind behördliche Maßnahmen gegen #Cybercrime nachhaltig - so beim Infostealer "#Lumma", der im letzten Jahr durch #Europol abgeschaltet wurde, indem 400.000 infizierte Rechner identifiziert und über Sinkholing aus dem Netz genommen wurden.

    Mittlerweile aber soll der Informationsdiebstahl durch "Lumma" wieder in vollem Gange sein - technische Infrastruktur lässt sich eben doch recht zügig wieder aufbauen, wenn man will:

    heise.de/news/Comeback-von-Lum #cybersecurity

  24. 2025-07-15 (Tuesday): #LummaStealer infection with #SecTopRAT.

    A #pcap of the #Lumma traffic and #SecTop #RAT activity, the #malware/artifacts from an infection, and the associated IOCs are available at malware-traffic-analysis.net/2