logo

Weekend Hunt

ID: 45340b09-fad9-55cf-9606-ab5312ab88d7

STIX ID: report--45340b09-fad9-55cf-9606-ab5312ab88d7

Feed Name: IntelInsights (Substack)

Threat Score
72/100

Date Published: 2024-11-30

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

Research links a Lumma infostealer sample to Amadey malware through shared, recently registered C2/distribution infrastructure, detailing hashes, URLs, domains, IPs, and an SSH key fingerprint while noting many nodes were offline at review time; observed TTPs include distribution via Telegram/cracked apps, malicious CAPTCHAs, and phishing, suggesting a tiered infrastructure serving multiple stealers by victim profile.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.