MIDDLEWARE Group: From ClickFix to Lumma Stealer
ID: 56b26bf7-6a2a-5091-affa-55f71540176d
STIX ID: report--56b26bf7-6a2a-5091-affa-55f71540176d
Feed Name: ThreatLocker Blog
ClickFix is a social-engineering technique that tricks users into pasting and executing verification commands (PowerShell on Windows or shell on macOS) which download a multi-stage payload. The attack chain described uses an initial PowerShell downloader that creates and runs an MSI which performs DLL sideloading (IDAT Loader) to execute PureRat/ZGRat and later deploy the Lumma information stealer that exfiltrates browser and wallet data to Telegram; the report includes detailed technical analysis, IPs/domains/hashes, file paths, and recommended mitigations using ThreatLocker controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
