Lumma Stealer on the Rise: How Telegram Channels Are Fueling Malware Proliferation
ID: 7e41c108-031e-5688-ba97-297595986016
STIX ID: report--7e41c108-031e-5688-ba97-297595986016
Feed Name: McAfee Labs Blog
Threat Score
This McAfee blog analyzes the Lumma Stealer malware campaign distributed through Telegram channels, detailing a multi-stage .NET/V C++ dropper that decrypts and injects payloads, a .NET infostealer and a clipper that hijacks cryptocurrency clipboard contents, and lists IOCs (multiple archive hashes, Telegram channel links, and the C2 domain marshal-zhukov.com) alongside observed TTPs used for persistence and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
