216.73.217.98

Lumma Stealer Malware Thrives as Unique Patterns Uncovered in the Infostealer's Domain Clusters

· Published 22/02/2025 00:33 · Modified 24/02/2025 09:08

Export JSON

Essential information

Published
22/02/2025 00:33
Modified
24/02/2025 09:08
Tags
2025-02-22 c2 infrastructure credential-theft domain clusters infostealer lumma stealer malspam malvertising sectoprat youtube
Related entities
17 techniques (mitre), 2 malware

Description

Recent research reveals command and control share specific technical characteristics, enabling mapping of entire infrastructure clusters. The 's logs are being shared for free on Leaky[.]pro, a new hacking forum, offering billions of stolen credential records. There's an alarming increase in malware spread via malicious links and infected files disguised in videos, comments, or descriptions. infections typically enable more extensive attacks, including ransomware deployment and espionage operations. The malware targets multiple Windows versions, stealing sensitive information like login credentials, browser data, chat logs, and cryptocurrency wallet details. Distribution methods include on popular search engines and with harmful attachments. Threat actors register clusters of 10-20 domains at a time, some used immediately while others age for up to two weeks.

External references