logo

Mapping latest Lumma infrastructure

ID: d70ee8af-25d7-549e-b781-9076c1c67ae8

STIX ID: report--d70ee8af-25d7-549e-b781-9076c1c67ae8

Feed Name: IntelInsights (Substack)

Threat Score
70/100

Date Published: 2025-10-13

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report documents an infrastructure hunt into the Lumma infostealer, starting from a reported C2 domain (nonsazv.qpon) and pivoting via URLScan and Validin to cluster hundreds of related C2 domains (notably *.qpon, .top, .xyz, .ru) and IPs, many running nginx/1.24.0 (Ubuntu) and hosted by Aeza (AS210644), ROUTE95 GREEN FLOID LLC (AS8254), Routerhosting, and Proton66. Using certificate fingerprint pivots, the analysis reinforces that Lumma operators rely on concentrated bulletproof hosting infrastructure despite aggressive domain rotation, and it provides a linked IoC list for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.