216.73.216.6

Fake Cloudflare Verification Results in LummaStealer Trojan Infections

· Published 20/03/2025 04:39 · Modified 20/03/2025 09:13

Export JSON

Essential information

Published
20/03/2025 04:39
Modified
20/03/2025 09:13
Tags
2025-03-20 cloudflare infostealer javascript injection lummac2 lummastealer powershell trojan wordpress
Related entities
4 observables, 10 techniques (mitre), 2 malware

Description

A malicious campaign targeting Windows users through websites is deploying the . Attackers use fake verification prompts to trick users into running malicious commands. The infection is spread through compromised plugins or injected JavaScript in legitimate files. Victims are directed to execute commands that download and install the malware, which can steal sensitive data like login credentials and cryptocurrency information. The attackers also create hidden admin users in infected sites for persistence. Multiple variants of this attack have been observed, with some using URL shortening services to obfuscate malicious links. Website owners are advised to keep software updated, use strong passwords, and implement 2FA to mitigate risks.

External references