216.73.217.22

Your Data Is Under New Management: The Rise of LummaStealer

· Published 18/12/2024 18:13 · Modified 18/12/2024 19:37

Export JSON

Essential information

Published
18/12/2024 18:13
Modified
18/12/2024 19:37
Tags
2024-12-18 lummastealer malware-as-a-service (maas) phishing python social engineering
Related entities
16 techniques (mitre), 1 malware

Description

, a relatively new information-stealing malware, has gained prominence since 2022 for its ability to collect sensitive data from Windows systems. Marketed as Malware-as-a-Service (MaaS) on underground forums, it targets individuals, cryptocurrency users, and small to medium-sized businesses. The malware employs various infection vectors, including emails, cracked software, and malicious downloads. It harvests credentials, cookies, cryptocurrency wallets, and system information, exfiltrating data to remote servers. Recent campaigns have shown increased sophistication in tactics and the use of legitimate platforms like Steam and Dropbox to evade detection. The malware's accessibility through MaaS has made it popular among diverse threat actors, complicating attribution efforts.

External references