Lumma Stealer – Tracking distribution channels
ID: 8654e59b-bd21-5120-af57-29727621408a
STIX ID: report--8654e59b-bd21-5120-af57-29727621408a
Feed Name: Securelist by Kaspersky
Date Published: 2025-04-21
Date Updated: 2026-04-29
Author: Elsayed Elrefaei, Ahmed Daif, Mohamed Ghobashy
This report analyzes Lumma Stealer, an actively distributed information-stealer marketed as LummaC2, focusing on a fake-CAPTCHA campaign that tricks users into executing clipboard-pasted PowerShell or mshta-based commands. It documents the full infection chains (CDN-hosted scripts, ZIP extraction, NSIS/AutoIt loaders, overlay injection, DLL sideloading), anti-analysis and persistence techniques, C2 communication patterns, and provides IoCs observed during incident response to assist detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
