Threats Tagged 'lumma'
View all threats tagged with 'lumma'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'lumma'
Click on any threat for detailed analysis and mitigation recommendations
A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency. Join the discussion | AlienVault OTX General | 07/03/2026, 02:26:44 UTC Added: 07/03/2026, 07:06:38 UTC |
Since late 2025, cybercriminals have been exploiting Wallpaper Engine, a popular live wallpaper application on Steam, to distribute malware through Steam Workshop. Attackers target primarily Chinese and Russian gamers by embedding malicious code within application wallpapers shared on the platform. These compromised wallpapers deliver various malware types including infostealers, backdoors, crypto miners, and ransomware. One analyzed sample dropped DarkKomet backdoor while hijacking Steam sessions to steal account credentials. The malware modifies system libraries to locate Steam installations and exfiltrate data to attacker-controlled servers. Compromised accounts are then used to upload additional malicious wallpapers. The diverse malware families suggest multiple independent hacking groups are exploiting this distribution method. Infected wallpapers received thousands of downloads before removal, with 89% of infections occurring in China. Join the discussion | AlienVault OTX General | 06/16/2026, 09:50:13 UTC Added: 06/16/2026, 11:30:21 UTC |
Researchers uncovered a massive fraud ecosystem targeting the 2026 FIFA World Cup, identifying over 4,300 fraudulent domains impersonating FIFA's official website since August 2025. At the center operates GHOST STADIUM, a Chinese-speaking threat actor running a sophisticated phishing campaign across 300+ domains using a pixel-perfect clone of FIFA's authentication system. The operation harvests credentials, sells fake tickets, and processes payments through five distinct channels including cryptocurrency. Estimated losses from premium ticket fraud alone range from $71 million to $474 million, with total campaign losses potentially reaching billions. Six distinct fraud schemes operate in parallel: credential phishing, fake ticket sales, counterfeit merchandise, fake streaming platforms, fraudulent betting sites, and infostealer-driven credential theft. Over 2,513 FIFA account credentials are already circulating on dark-web markets. The campaign exploits Facebook advertising as its primary distribution chann... Join the discussion | AlienVault OTX General | 05/27/2026, 11:33:17 UTC Added: 05/27/2026, 14:18:34 UTC |
Five malicious NuGet packages published under account bmrxntfj impersonate Chinese .NET libraries to deploy an infostealer targeting browser credentials, cryptocurrency wallets, SSH keys, and local files. The packages typosquat legitimate Chinese UI and infrastructure libraries, grafting .NET Reactor-protected payloads onto decompiled legitimate code. The campaign uses version rotation to evade hash-based detection, with 219 of 224 total versions unlisted but fetchable. The stealer targets 12 browsers, 8 desktop crypto wallets, and 5 browser wallet extensions, exfiltrating data to a newly-registered C2 domain. With approximately 65,000 downloads across all versions, the campaign puts tens of thousands of developer workstations and CI/CD build servers at risk. The payload executes through .NET module initializers, hooks the CLR JIT compiler, and supports cross-platform infection including Linux and macOS infrastructure. Join the discussion | AlienVault OTX General | 05/07/2026, 17:05:04 UTC Added: 05/08/2026, 09:06:23 UTC |
A malicious campaign exploiting Google Groups to distribute Lumma Stealer and Ninja Browser malware has been uncovered. The attackers infiltrate industry-related forums, posting seemingly legitimate technical discussions with embedded malicious download links. For Windows users, the payload is Lumma Stealer, a credential-harvesting malware. Linux users are directed to download a trojanized Chromium-based browser called Ninja Browser, which installs malicious extensions and persistence mechanisms. The campaign utilizes Google's trusted ecosystem to bypass security measures and increase user confidence. Over 4,000 malicious Google Groups and 3,500 Google-hosted URLs have been identified in this global operation, posing significant risks to organizations including credential theft, account takeover, and remote command execution. Join the discussion | AlienVault OTX General | 02/16/2026, 10:44:40 UTC Added: 02/16/2026, 11:04:11 UTC |
A widespread campaign is distributing the RenEngine loader malware disguised as pirated games and software. The loader uses a modified Ren'Py game engine to deliver payloads like Lumma and ACR stealers. It employs sophisticated techniques including sandbox evasion, process injection, and modular design. The infection chain involves decrypting and launching malicious code through legitimate applications. RenEngine has affected users globally, with Russia, Brazil, Turkey, Spain and Germany most impacted. The campaign highlights risks of pirated software and the need for robust security measures. Join the discussion | AlienVault OTX General | 02/11/2026, 16:29:19 UTC Added: 02/11/2026, 22:01:15 UTC |
The Lumma infostealer is a sophisticated malware distributed as Malware-as-a-Service, targeting Windows systems. It primarily steals sensitive data such as browser credentials, cryptocurrency wallets, and VPN/RDP accounts. Lumma is often used in the initial stages of multi-vector attacks, including ransomware and network breaches. The malware is distributed through phishing sites, disguised as pirated software, and uses complex techniques like NSIS packaging, AutoIt scripts, and process hollowing to evade detection. To combat this threat, organizations should implement behavior-based detection systems and integrate threat intelligence into their security strategies. Join the discussion | AlienVault OTX General | 11/27/2025, 18:43:56 UTC Added: 11/27/2025, 19:03:18 UTC |
The German hosting provider aurologic GmbH has become a critical infrastructure hub for multiple high-risk and sanctioned cybercrime networks, including entities involved in disinformation and malware campaigns. Despite public scrutiny and sanctions, aurologic continues to provide upstream transit services, enabling threat actors to maintain operational stability. The provider's approach to abuse handling is reactive and legally compliant rather than proactive, allowing malicious infrastructure to persist. This situation highlights challenges in accountability within the hosting ecosystem and the risks posed by infrastructure neutrality when it enables cybercrime. Numerous suspicious domains linked to aurologic-hosted networks have been identified, associated with malware families and threat actor tools. European organizations, especially in Germany, face increased risks due to this infrastructure's stability and continued operation. Mitigation requires enhanced monitoring of traffic from these domains, collaboration with upstream providers, and pressure on hosting providers to adopt proactive abuse prevention. Countries with significant internet infrastructure and cybercrime targets in Europe are most likely to be affected. Join the discussion | AlienVault OTX General | 11/06/2025, 18:51:59 UTC Added: 11/06/2025, 20:20:40 UTC |
Check Point Research identified a sophisticated malware distribution campaign on YouTube called the YouTube Ghost Network. This network uses over 3,000 malicious videos to spread infostealer malware, primarily Lumma and Rhadamanthys, targeting users seeking game cheats and pirated software. The operation involves compromised YouTube accounts assigned roles such as video uploaders, community posters, and interaction simulators. Active since 2021, the campaign saw a significant rise in activity in 2025. It employs evasion techniques including password-protected archives and frequent updates to malware payloads and command-and-control infrastructure. The campaign highlights evolving malware distribution tactics on popular platforms. Join the discussion | AlienVault OTX General | 10/23/2025, 13:51:01 UTC Added: 10/24/2025, 11:25:07 UTC |
This analysis delves into the HijackLoader malware campaign, which has gained prominence since 2023 for its sophisticated payload delivery and evasion techniques. The campaign initiates with a CAPTCHA-based phishing attack, progressing through multiple stages of obfuscated PowerShell scripts. It employs advanced anti-analysis methods, including anti-VM checks and registry manipulation. The final payload, typically an infostealer like NekoStealer or Lumma, is delivered via a multi-stage process involving packed .NET executables and protected DLLs. The loader's evolution and its role in the broader malware-as-a-service ecosystem underscore the need for organizations to focus on detecting initial access and intermediate stages rather than just final payloads. Join the discussion | AlienVault OTX General | 09/12/2025, 14:56:55 UTC Added: 09/12/2025, 19:29:21 UTC |
Showing 1 to 10 of 16 results