logo

Dissecting Lumma Malware: Analyzing the Fake CAPTCHA and Obfuscation Techniques – Part 2

ID: a9ce5ea7-c8fc-5d12-8076-70268d902e24

STIX ID: report--a9ce5ea7-c8fc-5d12-8076-70268d902e24

Feed Name: infostealers.com

Threat Score
70/100

Date Published: 2024-09-18

Date Updated: 2026-04-28

Author: Alon Gal

...
...

This technical analysis dissects the Lumma Stealer infection chain starting from a fake CAPTCHA page: an mshta-delivered HTA/PE contains embedded obfuscated JavaScript that decodes layered payloads (including AES-encrypted PowerShell), downloads a malicious ZIP masquerading as legitimate software, and ultimately executes Lumma via process injection into BitLockerToGo. The report documents decoding steps, tooling used (CyberChef, DIE, Ghidra, Hollows Hunter), dynamic behavior, and provides IOCs—SHA256 hashes, malicious URLs, and multiple C2 domains—for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.