216.73.216.6

Lumma Stealer's GitHub-Based Delivery Explored via Managed Detection and Response

· Published 31/01/2025 09:52 · Modified 31/01/2025 10:39

Export JSON

Essential information

Published
31/01/2025 09:52
Modified
31/01/2025 10:39
Tags
2025-01-31 information-stealing lumma stealer
Related entities
1 intrusion sets (apt), 19 techniques (mitre), 4 malware

Description

Trend Micro's Managed XDR team investigated a sophisticated campaign distributing through GitHub. The attackers exploited GitHub's release infrastructure to deliver various malware, including SectopRAT, Vidar, and Cobeacon. The campaign used compromised websites for redirection to GitHub-hosted malicious payloads. The malware exfiltrated sensitive data, connected to C&C servers, and employed evasion techniques. The tactics show similarities with the Stargazer Goblin group, known for using compromised websites and GitHub for payload distribution. The attack chain involved multiple stages, including initial access through GitHub, execution of malware, and subsequent deployment of additional tools. The campaign highlights the evolving distribution methods of and the importance of proactive security measures.

External references