Prospering Lumma
ID: 6ffc8e16-bfff-53e1-a731-c8de10079aa1
STIX ID: report--6ffc8e16-bfff-53e1-a731-c8de10079aa1
Feed Name: IntelInsights (Substack)
Investigation tracks an active Lumma infostealer campaign tied to AS200593 (Prospero), enumerating hosting IPs, domains, and distribution paths (notably /1337 and /update) that deliver payloads like TORRENTOLD-1.exe and TPB-1.exe via Apache hosts and Cloudflare. Using urlscan, Validin, and other pivots, the author maps additional infrastructure across 91.202.233.0/24 and 91.215.85.0/24, shares specific URLs and IPs, notes crawler blocking behavior, and links an external IoC list for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
