logo

Beware Weaponized YouTube Channels Spreading Lumma Stealer

ID: 6343101a-d5f3-552e-927b-1cc26cd7373a

STIX ID: report--6343101a-d5f3-552e-927b-1cc26cd7373a

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-09

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers observed a campaign spreading a Lumma Stealer variant through YouTube channels that host cracked-software tutorials; links in video descriptions point to ZIP files on file-sharing services that contain LNK files which trigger PowerShell to fetch an obfuscated .NET loader from GitHub, ultimately deploying Lumma to harvest credentials, browser data, and system information. The loader employs environment checks (anti-debugging, sandbox/VM detection) and payload injection techniques, and the latest variant uses HTTPS for exfiltration; Fortinet published IoCs and recommended cautious sourcing and security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.