216.73.217.22

Fake Browser Updates delivering BitRAT and Lumma Stealer

· Published 03/06/2024 11:26 · Modified 03/06/2024 11:48

Export JSON

Essential information

Published
03/06/2024 11:26
Modified
03/06/2024 11:48
Tags
2024-06-03 bitrat lumma stealer
Related entities
13 observables, 17 techniques (mitre), 2 malware

Description

This report details a malicious campaign where adversaries used fake browser update prompts to lure victims into downloading and executing malware. The infection chain begins with injected malicious JavaScript code on compromised websites that redirect users to pages mimicking legitimate browser update sites. These fake update sites host ZIP archives containing PowerShell scripts responsible for downloading and executing and malware. The report provides in-depth analysis of the attack flow, payload characteristics, encryption routines, and command-and-control infrastructure leveraged by these malware families.

External references