logo

Lumma Stealer on the Rise: How Telegram Channels Are Fueling Malware Proliferation

ID: 7e41c108-031e-5688-ba97-297595986016

STIX ID: report--7e41c108-031e-5688-ba97-297595986016

Feed Name: McAfee Labs Blog

Threat Score
72/100

Date Published: 2024-11-21

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This McAfee blog analyzes the Lumma Stealer malware campaign distributed through Telegram channels, detailing a multi-stage .NET/V C++ dropper that decrypts and injects payloads, a .NET infostealer and a clipper that hijacks cryptocurrency clipboard contents, and lists IOCs (multiple archive hashes, Telegram channel links, and the C2 domain marshal-zhukov.com) alongside observed TTPs used for persistence and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.