home.social

#lummastealer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lummastealer, aggregated by home.social.

fetched live
  1. EU, UK sanction Russian cyberespionage networks over destructive attacks

    European governments sanctioned Russian individuals and organizations Monday over what they said was a years-long campaign of cyberespionage…
    #Europe #EU #Austria #cyberespionage #Cyprus #Energy #EuropeanUnion #Finland #fsb #Germany #gru #lummastealer #Netherlands #Poland #Romania #Russia #secretblizzard #Slovakia #turla #unitedkingdom(u.k.)
    europesays.com/europe/93170/

  2. EU, UK sanction Russian cyberespionage networks over destructive attacks

    European governments sanctioned Russian individuals and organizations Monday over what they said was a years-long campaign of cyberespionage…
    #EuropeSays #Russia #Austria #cyberespionage #Cyprus #Energy #EuropeanUnion #Finland #FSB #Germany #gru #lummastealer #Netherlands #Poland #Romania #secretblizzard #Slovakia #turla #unitedkingdom(u.k.)
    europesays.com/russia/39406/

  3. Microsoft Utility MSHTA Fuels Malware Surge via Lumma Stealer Campaigns

    Malware campaigns are on the rise, fueled by the Microsoft Utility MSHTA, which is being exploited to spread info stealers like Lumma Stealer and Amatera. This sneaky tactic is just the latest example of how cybercriminals are abusing a long-standing Windows feature to wreak havoc.

    osintsights.com/microsoft-util

    #LummaStealer #Mshta #MalwareLoader #InfoStealer #Amatera

  4. Vercel Breach Exposes Additional Customer Accounts

    A recent Vercel breach exposed additional customer accounts after a malicious chain of events began with a compromised employee account at Context.ai, which was likely triggered by a simple online search for Roblox scripts. The breach highlights the risks of malware distribution and token theft, with threat intel pointing to a sophisticated…

    osintsights.com/vercel-breach-

    #VercelBreach #EmergingThreats #SupplyChain #MalwareOperations #LummaStealer

  5. Dal Roblox script al breach di Vercel: come un infostealer ha quasi compromesso la supply chain di Next.js

    Un dipendente di Context.ai infettato da Lumma Stealer tramite script Roblox ha aperto la porta a una potenziale supply chain attack su Vercel e Next.js. ShinyHunters rivendica il furto di codice sorgente, token NPM/GitHub e 580 record di dipendenti, offrendo il pacchetto per $2 milioni. Vercel conferma accesso limitato ma esclude compromissione dei framework open source.

    insicurezzadigitale.com/dal-ro

  6. Nowy wariant metody ClickFix – cyberprzestępcy rezygnują z Win+R na rzecz Win+X i Terminala Windows

    Badacze bezpieczeństwa z Microsoft Defender ostrzegają przed nowym wariantem kampanii malware, w której cyberprzestępcy za pomocą phishingu nakłaniają użytkowników do instalacji złośliwego oprogramowania typu infostealer (Lumma Stealer). Atak opiera się na technice ClickFix, polegającej na przekonaniu użytkownika do uruchomienia złośliwych poleceń PowerShell.TLDR: Schemat ataku jest dosyć prosty. Korzystając z socjotechniki...

    #Aktualności #Clickfix #LummaStealer #Microsoft #Windows #WindowsDefender

    sekurak.pl/nowy-wariant-metody

  7. CTM360 identifies an active campaign leveraging Google Groups and Google-hosted redirect chains to deliver Lumma Stealer (Windows) and a trojanized Chromium fork branded “Ninja Browser” (Linux).
    Technical highlights:
    • 950MB padded executable (null-byte inflation)
    • AutoIt loader reconstruction
    • Memory-resident payload execution
    • Multipart/form-data POST exfiltration
    • Malicious extension “NinjaBrowserMonetisation”
    • XOR + Base56-like JS obfuscation
    • Scheduled task persistence
    • Russian search engine default modification

    This campaign reinforces a critical shift: SaaS platforms are now delivery infrastructure.
    Defensive priorities:
    – IoC blocking at firewall + EDR
    – Redirect chain inspection
    – Extension audit controls
    – Endpoint scheduled task monitoring

    How are you adjusting detection engineering for SaaS-based malware distribution?
    Engage below.

    Source: ctm360.com/reports/ninja-brows

    Follow @technadu for ongoing threat intelligence coverage.

    #ThreatIntel #MalwareResearch #DetectionEngineering #SOCOperations #EDR #CloudSecurity #SaaSAbuse #LummaStealer #LinuxThreats #CTM360 #IncidentResponse

  8. DNS-based staging via ClickFix represents tactical evolution.

    Per Microsoft:
    • Cmd.exe → nslookup execution
    • Hardcoded external DNS resolver
    • Payload embedded in DNS Name: response
    • ZIP retrieval from azwsappdev[.]com
    • Python-based reconnaissance
    • VBScript persistence via Startup LNK
    • ModeloRAT deployment
    • Lumma Stealer distribution via CastleLoader (GrayBravo)

    Campaign telemetry also discussed by Bitdefender and Kaspersky.

    DNS offers:
    • Reduced dependency on HTTP
    • Traffic blending with legitimate queries
    • Lightweight validation signaling

    Detection priorities:
    • Anomalous nslookup patterns
    • External DNS resolver usage
    • Suspicious Startup LNK creation
    • DNS response content inspection

    Is your EDR correlating DNS queries with process lineage?
    Engage below.
    Follow @technadu for advanced threat analysis.

    #ThreatIntel #ClickFix #DNSStaging #ModeloRAT #LummaStealer #CastleLoader #DetectionEngineering #BlueTeam #SOC #Infosec #CyberOperations #MalwareAnalysis

  9. Compromise Report 2026 de Lumu revela un giro hacia ciberataques más silenciosos y persistentes

    Compromise Report 2026 de Lumu revela un giro hacia ciberataques más silenciosos y persistentes
    San José, 10 feb (elmundo.cr) – Lumu Technologies, la compañía de ciberseguridad pionera en el modelo de Continuous Compromise Assessment®, presentó hoy su informe Compromise [...]

    #Ciberataques #CienciaYTecnología #CompromiseReport2026 #DeathRansom #LummaStealer #LumuTechnologies

    elmundo.cr/cienciaytecnologia/

  10. 2026-02-01 (Sunday): It's easy enough to find #LummaStealer malware samples.

    Just do a Google search for cracked versions of popular software and specify site:drive.google.com.

    Details on today's haul at github.com/malware-traffic/ind

  11. Unmasking Lumma Malware in 2026 L umma malware, also known as Lumma infostealer, is a type of malicious software created for stealing personal information from the computers on which it is installe...

    #malware-analysis #malware #cyber-security-awareness #lumma-stealer #cybersecurity

    Origin | Interest | Match
  12. 2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at malware-traffic-analysis.net/2

    I've also added three other blog entries from infections I generated in my lab on Tuesday, 2026-01-20. Those can be found at malware-traffic-analysis.net/2

    Those three other entries cover #LummaStealer, #VIPRecovery, and #Xworm. The VIP Recovery and Xworm infections followed the same chain of events, which includes #steganography through base64 text embedded in an image.

  13. Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain
    #LummaStealer
    isc.sans.edu/diary/32628

  14. 2026-01-01 (Thursday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the #Lumma #Stealer files, and a list of IOCs are available at malware-traffic-analysis.net/2

    Lumma Stealer C2 domain: offenms[.]cyou

    The follow-up malware is using memory-scanner[.]cc for its C2 traffic, just like I saw on 2025-12-30. But this follow-up malware also used another C2 domain: communicationfirewall-security[.]cc

  15. 2025-12-30 (Tuesday): #LummaStealer infection with follow-up malware.

    A #pcap of the infection traffic, the associated #Lumma with follow-up #malware samples, and some IOCs are available at www.malware-traffic-analysis.net/2025/12/30/index.html

    I don't know what the follow-up malware is, but unlike Lumma Stealer, the follow-up malware was made persistent.

    Big thanks to VirusTotal on this, because I was able to grab VirusTotal's CAPE Sandbox analysis of the Lumma Stealer sample, and it shows the URLs from the HTTPS traffic that I can't get in my lab.

    If anyone knows what the follow-up malware is, please share that info!

  16. Y en un giro de los acontecimientos, un grupo rival (de infostealer presumiblemente) ataca y expone a la luz las identidades y detalles de los miembros de #Lumma, con información tan sensible como datos bancarios o número de pasaporte. Esto se une al compromiso de las cuentas de Telegram del grupo criminal. Esto, claro, ha provocado el éxodo de clientes a plataformas de malware as a service alternativas. Y yo viendo esto con palomitas.

    Ahora me explico la caída en picado en la actividad de Lumma.

    #lummastealer #ciberseguridad #cybersecurity

  17. I've considered deploying more HTTP-referrer based URL-policies. In particular, links from social platforms' comments: YouTube, GitHub Issues, Reddit, Instagram, etc.

    I have a lookup in my SIEM to flag traffic referred from a comment. But it's probably time to shift-to-protect.

    Anyone else done this in their SASE/proxy? I think it's already common in education.

    And we're at the mercy of these platforms' URL params. So I'd need some observability on the pattern matching.

    research.checkpoint.com/2025/y

    #phishing #infosec #LummaStealer

  18. Rival hackers have doxxed the alleged operators behind #LummaStealer, one of the biggest data-theft malware services. The leaks have caused internal chaos and slowed its growth.

    Read: hackread.com/rival-hackers-dox

    #CyberSecurity #Malware #InfoStealers #InfoSec #CyberCrime

  19. RE: infosec.exchange/@patrickcmill

    For those interested in the doxxing published on website named ‘Lumma Rats, here's the site:

    lummakrysy[.]rip

    #lumma #LummaStealer #doxxing #threatintel

  20. 🚨 Cyber Threat Update: Lumma Stealer Doxxing
    A targeted underground exposure campaign impacted Lumma Stealer (Water Kurita) operators, causing:
    - 🔻 Reduced malware activity
    - 🔄 Customer migration to Vidar, StealC, Amadey
    - ⚔️ Intensified competition among infostealer MaaS platforms
    What’s your take - is this a turning point for underground malware markets?
    💬 Join the conversation & follow TechNadu for actionable cyber intelligence.

    #CyberSecurity #Infostealer #LummaStealer #WaterKurita #Malware #MaaS #ThreatIntel #Vidar #StealC #Amadey #DarkWeb #CyberCrime #TechNadu #CyberUpdate

  21. 2025-10-01 (Wednesday) I've posted #malware samples and a #pcap of the post-infection traffic from an infection by possible #Rhadamanthys malware at malware-traffic-analysis.net/2

    This is from a campaign that disguises files as cracked versions of popular software

    I usually see #LummaStealer from this, but lately, it's been Rhadamanthys.

  22. 2025-09-24 (Wednesday): #LummaStealer infection with follow-up malware, possibly #Ghostsocks or #GoBackdoor.

    A #pcap of the infection traffic, malware samples, and list of indicators are available at malware-traffic-analysis.net/2

  23. 2025-09-03 (Wednesday): #Kongtuke injected script leads to fake CAPTCHA page.

    The fake CAPTCHA page provides #ClickFix style instructions to run a malicious command/script for #LummaStealer

    Clipboard hijacking (pastejacking) at its finest!

    A #pcap of the infection traffic, the associated malware, and a list of indicators are at malware-traffic-analysis.net/2

  24. Since end of August we observe infamous #LummaStealer communicating with DGA-like domain names 🤖👀, for example ⤵️

    oneflof .ru
    georgej .ru
    bastxtu .top
    larpfxs .top
    ...

    We have seen such domains across 3 distinct IP address, all sharing the same SSL certificate
    (SHA1 fingerprint: 497f2c84c223602794cbe4481e2641bdb55d81a7):

    129.226.128.168:443 (Tencent 🇨🇳)
    31.220.109.219:443 (Hostinger 🇺🇸)
    165.227.143.219:443 (DigitalOcean🇺🇸)

    Malware sample:
    📄bazaar.abuse.ch/sample/df0442c

    IOC:
    📡threatfox.abuse.ch/browse/malw

  25. Recent DTI research tracked a trojan using hosted PowerShell scripts, uncovering bulletproof hosting services and how #LummaStealer remains a threat.

    Read the full report: dti.domaintools.com/hunting-fo

    #Cybersecurity #ThreatIntel #Malware #BlueTeamsec

  26. 2025-08-15 (Friday): Here are some images from a post I wrote for my employer on other social media platforms.

    This is from a #LummaStealer infection that led to #SectopRAT (#ArechClient2).

    A #pcap of the infection traffc, along with the associated #malware and artifacts are available at malware-traffic-analysis.net/2

  27. 2025-08-13 (Wednesday): #LummaStealer infection. The associated #malware, artifacts, a #pcap of the #Lumma Stealer traffic, and indicators of compromise are available at malware-traffic-analysis.net/2

Share on Mastodon

Enter the server where you have an account.