Skip to main content

Threats Tagged 'lummastealer'

View all threats tagged with 'lummastealer'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: lummastealer

Threats Tagged 'lummastealer'

Click on any threat for detailed analysis and mitigation recommendations

RemusStealer is a malware-as-a-service program exhibiting multiple similarities to LummaStealer, including anti-virtual machine checks, credential theft tactics, and Application-Bound Encryption bypass methods. A key distinction is RemusStealer's use of Ethereum smart contracts for C2 communications instead of Steam or Telegram dead drop resolvers. Written in Go, the stealer performs extensive system discovery, gathering information about antivirus products, hardware specifications, and operating systems. It employs hidden desktop environments to evade detection while launching Microsoft Edge and Brave browser processes on non-primary window stations to steal credential files. The malware establishes connections to suspicious domains ending in .shop or .biz and communicates with Ethereum-related infrastructure. This evolution demonstrates attackers' increasing sophistication in leveraging blockchain technology to masquerade malicious communications through smart contracts.

Join the discussion

A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking.

Join the discussion

A large-scale malware campaign tracked as TroyDen's Lure Factory has been identified distributing LuaJIT-based infostealers through over 300 delivery packages hosted on GitHub. The operation uses AI-generated lure names incorporating obscure biological taxonomy and medical terminology to target developers, gamers, Roblox players, and crypto users. The malware employs a two-component design with a renamed LuaJIT runtime and encrypted Lua payload that evades sandbox detection through anti-analysis checks and extreme sleep delays. Upon execution, it disables proxy detection, captures desktop screenshots, performs geolocation, and exfiltrates data to C2 servers in Frankfurt. The infrastructure demonstrates scalability with multiple IP addresses serving identical encrypted commands, while maintaining simultaneous campaigns across gaming cheats, developer tools, phone trackers, and VPN crackers.

Join the discussion

A ClickFix-style phishing campaign leveraged social engineering to trick users into executing obfuscated PowerShell commands that downloaded and installed a malicious MSI payload from a remote server. The attack employed a sophisticated multi-stage infection chain utilizing DLL sideloading techniques with renamed legitimate binaries to execute malicious components. The final payload deployed HijackLoader to deliver a Lumma-style information stealer designed for credential harvesting and data exfiltration. The campaign utilized multiple command-and-control domains and infrastructure hosted on specific IP addresses. Mitigation measures include blocking identified artifacts, enhancing user awareness about ClickFix social engineering tactics, implementing endpoint detection for suspicious PowerShell activity and unsigned DLL sideloading, and isolating compromised systems for remediation.

Join the discussion

Insikt Group identified five distinct clusters using the ClickFix social engineering technique for initial access. These clusters impersonate various services like Intuit QuickBooks and Booking.com, demonstrating operational variance but similar core techniques. ClickFix manipulates victims into executing malicious commands within native system tools, bypassing traditional security controls. The methodology has become a standardized template for cybercriminals and APT groups. Campaigns target diverse sectors and use sophisticated obfuscation and living-off-the-land tactics. Defenders are advised to implement aggressive behavioral hardening and user awareness training to mitigate these threats.

Join the discussion

ACRStealer, a sophisticated Malware as a Service, has evolved with enhanced evasion techniques and C2 communication strategies. It employs low-level syscalls and AFD for stealthy operations, bypassing user-mode hooks. The malware uses layered communication, establishing raw TCP connections followed by SSL/TLS over SSPI. ACRStealer's data-stealing capabilities are extensive, targeting browsers, Steam accounts, and performing victim fingerprinting. It can execute secondary payloads and capture screenshots. The malware shows an active infection pattern in countries like the USA, Mongolia, and Germany, communicating with specific IP addresses and domains. Recent developments indicate a shift to LummaStealer, suggesting ongoing threat actor activities targeting gaming platforms and social media.

Join the discussion

A malicious campaign is targeting indie game platforms Itch.io and Patreon by posting fake update links in comments, which lead to downloads of LummaStealer malware. This malware uses advanced anti-analysis techniques to evade detection, including checks for virtual machines, specific usernames, and malware analysis processes. The payload is delivered via a nexe-compiled JavaScript file that drops and loads a DLL variant of LummaStealer. Despite efforts to remove malicious accounts, attackers continuously create new ones, indicating an ongoing and persistent threat. The campaign primarily targets users seeking game updates, exploiting trust in indie game communities. No known exploits in the wild have been reported yet, but the malware’s stealth and persistence pose a medium-level risk. European organizations involved in gaming, digital content creation, or using these platforms could be impacted, especially those with less mature security controls. Mitigation requires targeted detection of fake update links, monitoring of platform comments, and enhanced endpoint defenses against DLL injection and obfuscated JavaScript. Countries with active indie game development and strong Patreon/Itch.

Join the discussion

GhostSocks is a Malware-as-a-Service (MAAS) that converts compromised devices into residential proxies, enabling threat actors to bypass anti-fraud mechanisms. Introduced in October 2023, it gained popularity after partnering with LummaStealer in February 2024. The malware, coded in Golang, uses obfuscation techniques and can be built as a 32-bit DLL or executable. It doesn't implement persistence mechanisms but focuses on SOCKS5 functionality. GhostSocks uses a configuration file or hardcoded config to connect to C2 servers, randomly generates credentials, and establishes a SOCKS5 connection using open-source libraries. Despite law enforcement actions against related platforms, GhostSocks continues to operate, posing ongoing risks of double victimization and long-term network access for cybercriminals.

Join the discussion

The GreedyBear attack group has launched a massive crypto theft operation, utilizing 150 weaponized Firefox extensions, nearly 500 malicious executables, and numerous phishing websites. Their tactics include Extension Hollowing to bypass marketplace security, distributing various malware families, and creating scam sites masquerading as crypto products. The campaign's infrastructure is consolidated to a single IP address, suggesting a centralized backend. The group has expanded from its earlier Foxy Wallet campaign and shows signs of potential growth beyond Firefox. The attackers are leveraging AI to scale their operations, making it challenging for traditional security measures to keep up. The campaign has reportedly stolen over $1 million from victims.

Join the discussion

Threat actors are exploiting user fatigue with anti-spam mechanisms through a technique called ClickFix. This method involves compromising websites and embedding fraudulent CAPTCHA images, which, when solved by unsuspecting users, lead to the execution of malicious code. The attack chain typically includes PowerShell commands and the use of legitimate Windows tools to download and execute additional payloads. Common malware delivered through this technique includes Lumma Stealer, NetSupport RAT, and SectopRAT. The success of ClickFix relies heavily on social engineering and user interaction, making user education and awareness crucial in mitigating these attacks. Recommendations include training users to recognize suspicious requests, restricting PowerShell execution, and deploying advanced EDR solutions.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: lummastealer
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses