Behind the Curtain: How Lumma Affiliates Operate
ID: a9970bb4-e0be-5f69-a19f-e3e882bc384d
STIX ID: report--a9970bb4-e0be-5f69-a19f-e3e882bc384d
Feed Name: Recorded Future Blog
This report analyzes the Lumma infostealer MaaS and its affiliates, revealing a large, resilient, and interconnected information-stealing ecosystem that leverages proxies, VPNs, anti-detect browsers, crypting/exploit services, SMS/phone services, and underground forums to distribute malware, monetize stolen data, and run parallel scams (including rental fraud). Insikt Group documents previously unreported tooling (e.g., cracked email validators, phishing page generators), the use of additional stealers (Vidar, Stealc, Meduza), hosting and AV-testing services, and provides IoCs and ATT&CK mappings to help defenders detect and mitigate infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
