logo

Distribution of LummaC2 Infostealer Based on Legitimate Programs

ID: 8beaf178-b2ac-5612-91a1-d9723a6c0558

STIX ID: report--8beaf178-b2ac-5612-91a1-d9723a6c0558

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-11-06

Date Updated: 2026-04-26

Author: ATCP

...
...

LummaC2 is an actively distributed infostealer that exfiltrates browser credentials, email data, cryptocurrency wallet information, and auto-login program data to attacker C2 servers. Threat actors are embedding the malware into legitimate executables (growing sections and modifying code paths) and disguising samples with legitimate version, icon, and certificate metadata to evade detection; the report documents infection flows, sample behaviors, and supplies MD5 hashes and C2 URLs for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.