CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups
ID: 9699a4b1-6370-596a-a70e-560b06aa94f5
STIX ID: report--9699a4b1-6370-596a-a70e-560b06aa94f5
Feed Name: Bleeping Computer
CTM360 details a global campaign abusing Google Groups and Google-hosted redirectors to distribute Lumma Stealer (Windows) via oversized, passworded archives and an AutoIt-based loader, and a trojanized Chromium "Ninja Browser" for Linux that installs malicious extensions and silent persistence; the report includes IoCs (domains, IPs, SHA-256 hashes), attacker TTPs, and mitigation recommendations such as blocking IoCs, inspecting short/redirected URLs, and auditing scheduled tasks and browser extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
