logo

Lumma Stealer Chronicles: PDF-themed Campaign Using Compromised Educational Institutions' Infrastructure

ID: 412a7fd9-aa09-5eca-988a-f1e5778adc44

STIX ID: report--412a7fd9-aa09-5eca-988a-f1e5778adc44

Feed Name: CloudSEK Blog

Threat Score
72/100

Date Published: 2025-02-14

Date Updated: 2026-04-27

...
...

### Executive Summary This report documents an active campaign distributing Lumma Stealer via malicious .lnk files hosted on WebDAV servers that invoke mshta.exe and PowerShell to retrieve an AES-encrypted payload (Kompass-4.1.2.exe). The analysis details obfuscated JavaScript and PowerShell stages, C2 infrastructure (including novel cloaking via Steam profile content), MITRE ATT&CK mappings, IoCs (file hashes, domains, IPs, URLs), and targeted industries, highlighting the need for user awareness and detection of the noted indicators and techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.