logo

Malvertising campaign leads to info stealers hosted on GitHub

ID: 92167fd8-5fb1-583a-8fa9-63773ac6cf93

STIX ID: report--92167fd8-5fb1-583a-8fa9-63773ac6cf93

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2025-03-06

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence and Microsoft Security Experts

...
...

Microsoft Threat Intelligence identified a widespread malvertising campaign (tracked as Storm-0408) that redirected users of illegal streaming sites through multiple redirectors to payloads hosted on GitHub, Discord, and Dropbox; initial droppers established multi-stage infections that deployed information stealers (including Lumma and Doenerium variants), AutoIT-based loaders, and NetSupport RAT to perform system discovery, browser credential/DPAPI access, and data exfiltration. The report provides a full analysis of the redirection chain and infection stages, extensive IoCs (domains, URLs, IPs, file hashes, certificates), hunting queries for Defender/XDR and Sentinel, and recommended mitigations to detect and block the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.