Lumma Stealer Enhances Capabilities with New PowerShell Tools and Sophisticated Techniques
ID: 82cbe286-defe-55a6-919f-0990aa0fbcf9
STIX ID: report--82cbe286-defe-55a6-919f-0990aa0fbcf9
Feed Name: Cyber Press
The report details Lumma Stealer, a Malware-as-a-Service infostealer active since mid-2022 with a recent surge in activity; actors use deceptive fake CAPTCHA websites and social engineering to get victims to execute PowerShell-encoded commands that stage multi-stage, obfuscated payloads (including encrypted ZIPs, AutoIt scripts, shellcode, and PE files) to harvest credentials, session cookies, and cryptocurrency wallets before exfiltrating data and removing traces. The analysis emphasizes the malware's evolving delivery and obfuscation techniques, distribution via Telegram/documentation, and recommends combining behavioral endpoint protections, monitoring for suspicious PowerShell/process execution chains, and targeted user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
