logo

Exposing Lumma Stealer’s Second-Stage Infrastructure and C2 Servers with ASN and JA4X Pivoting

ID: da8991d4-8a15-5307-9c0f-8554d075d530

STIX ID: report--da8991d4-8a15-5307-9c0f-8554d075d530

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-03-12

Date Updated: 2026-04-28

...
...

This report details infrastructure-level hunting that uncovered a coordinated cluster of 17 Lumma Stealer second-stage servers spanning AS56971 and AS215607. The servers share identical nginx/1.24.0 (Ubuntu) headers, a reused Let's Encrypt JA4X certificate fingerprint, use .cc domains with tech-themed/typosquatted names, and communicate over port 443; the report provides IPs/domains IOCs, SQL search queries used to discover the hosts, and mitigation recommendations to monitor and block similar infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.