Beware Weaponized YouTube Channels Spreading Lumma Stealer
ID: 6343101a-d5f3-552e-927b-1cc26cd7373a
STIX ID: report--6343101a-d5f3-552e-927b-1cc26cd7373a
Feed Name: Dark Reading
Date Published: 2024-01-09
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers observed a campaign spreading a Lumma Stealer variant through YouTube channels that host cracked-software tutorials; links in video descriptions point to ZIP files on file-sharing services that contain LNK files which trigger PowerShell to fetch an obfuscated .NET loader from GitHub, ultimately deploying Lumma to harvest credentials, browser data, and system information. The loader employs environment checks (anti-debugging, sandbox/VM detection) and payload injection techniques, and the latest variant uses HTTPS for exfiltration; Fortinet published IoCs and recommended cautious sourcing and security awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
