logo

Prospering Lumma

ID: 6ffc8e16-bfff-53e1-a731-c8de10079aa1

STIX ID: report--6ffc8e16-bfff-53e1-a731-c8de10079aa1

Feed Name: IntelInsights (Substack)

Threat Score
72/100

Date Published: 2025-03-02

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

Investigation tracks an active Lumma infostealer campaign tied to AS200593 (Prospero), enumerating hosting IPs, domains, and distribution paths (notably /1337 and /update) that deliver payloads like TORRENTOLD-1.exe and TPB-1.exe via Apache hosts and Cloudflare. Using urlscan, Validin, and other pivots, the author maps additional infrastructure across 91.202.233.0/24 and 91.215.85.0/24, shares specific URLs and IPs, notes crawler blocking behavior, and links an external IoC list for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.