logo

Lumma Stealer – Tracking distribution channels

ID: 8654e59b-bd21-5120-af57-29727621408a

STIX ID: report--8654e59b-bd21-5120-af57-29727621408a

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-04-21

Date Updated: 2026-04-29

Author: Elsayed Elrefaei, Ahmed Daif, Mohamed Ghobashy

...
...

This report analyzes Lumma Stealer, an actively distributed information-stealer marketed as LummaC2, focusing on a fake-CAPTCHA campaign that tricks users into executing clipboard-pasted PowerShell or mshta-based commands. It documents the full infection chains (CDN-hosted scripts, ZIP extraction, NSIS/AutoIt loaders, overlay injection, DLL sideloading), anti-analysis and persistence techniques, C2 communication patterns, and provides IoCs observed during incident response to assist detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.