216.73.216.233

Tracking LummaC2 Infrastructure with Cats

· Published 30/05/2025 00:47 · Modified 30/05/2025 08:55

Export JSON

Essential information

Published
30/05/2025 00:47
Modified
30/05/2025 08:55
Tags
2025-05-30 cat-themed domains domain seizures infostealing malware infrastructure tracking lummac2 malware distribution risk scoring threat intelligence
Related entities
1 intrusion sets (apt), 4 techniques (mitre), 1 malware, 1 others

Description

The US Department of Justice and Microsoft disrupted infostealing-malware through , taking down over 2,300 associated domains. The FBI and CISA released an advisory detailing 's tactics and indicators of compromise, including 114 domains. Analysis of these domains revealed common registration patterns, such as using Eastern European names and specific mail server hostnames. Notably, several domains featured an 'About Cats' landing page, with 58 additional domains sharing this characteristic and having high risk scores. These domains are suspected of distributing and other malware strains. Despite the takedown efforts, 41 of these domains remain active, highlighting the need for continued vigilance against infrastructure.

External references