216.73.216.6

LummaStealer dropped via fake updates from itch.io and Patreon

· Published 08/12/2025 17:25 · Modified 21/12/2025 18:49

Export JSON

Essential information

Published
08/12/2025 17:25
Modified
21/12/2025 18:49
Tags
2025-12-08 anti-analysis fake updates indie games itch.io javascript obfuscation lummastealer nexe patreon
Related entities
5 observables, 11 techniques (mitre), 1 malware, 1 others

Description

A malicious campaign targeting indie game platforms like and has been discovered. Attackers are using newly created accounts to spam comments on legitimate games, claiming to offer game updates through links. These links lead to downloads containing malware. The malware uses multiple techniques, including checks for virtual machines, specific usernames, and processes associated with malware analysis. The payload is delivered through a -compiled JavaScript file, which drops and loads a DLL containing the variant. Despite efforts to remove malicious accounts, new ones continue to appear, indicating an ongoing campaign.

External references