216.73.217.22

Unmasking Lumma Stealer: Analyzing Deceptive Tactics with Fake CAPTCHA

· Published 21/10/2024 15:16 · Modified 21/10/2024 16:24

Export JSON

Essential information

Published
21/10/2024 15:16
Modified
21/10/2024 16:24
Tags
2024-10-21 cryptocurrency data exfiltration fake captcha fileless information-stealing lumma stealer maas powershell process-hollowing
Related entities
23 observables, 1 intrusion sets (apt), 10 techniques (mitre), 1 malware

Description

, a sophisticated malware, has evolved its tactics to employ verification for payload delivery. The malware exploits legitimate software and uses multi-stage techniques to evade detection. Its infection chain involves scripts, process hollowing, and the abuse of Windows tools like mshta.exe. targets sensitive data, including passwords, browser information, and wallet details. The campaign analysis reveals the malware's deceptive methods, from initial infection to . The threat actors utilize Content Delivery Networks for payload delivery and command and control servers for .

External references