logo

Lumma Stealer Enhances Capabilities with New PowerShell Tools and Sophisticated Techniques

ID: 82cbe286-defe-55a6-919f-0990aa0fbcf9

STIX ID: report--82cbe286-defe-55a6-919f-0990aa0fbcf9

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-05-12

Date Updated: 2026-04-19

Author: Mandvi

...
...

The report details Lumma Stealer, a Malware-as-a-Service infostealer active since mid-2022 with a recent surge in activity; actors use deceptive fake CAPTCHA websites and social engineering to get victims to execute PowerShell-encoded commands that stage multi-stage, obfuscated payloads (including encrypted ZIPs, AutoIt scripts, shellcode, and PE files) to harvest credentials, session cookies, and cryptocurrency wallets before exfiltrating data and removing traces. The analysis emphasizes the malware's evolving delivery and obfuscation techniques, distribution via Telegram/documentation, and recommends combining behavioral endpoint protections, monitoring for suspicious PowerShell/process execution chains, and targeted user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.