logo

From Shadow to Spotlight: The Evolution of LummaStealer and Its Hidden Secrets

ID: 2ce7a2fe-3dbc-5711-88ae-a56446b50aec

STIX ID: report--2ce7a2fe-3dbc-5711-88ae-a56446b50aec

Feed Name: Cybereason Blog

Threat Score
78/100

Date Published: 2025-04-11

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

This Cybereason report analyzes LummaStealer — a mature info‑stealer MaaS — detailing a newly observed mshta-based delivery that uses fake CAPTCHA phishing pages, multi-layer obfuscation (HEX/JS → obfuscated PowerShell → AES decryption → XOR/Base64 → in‑memory .NET assembly), AMSI bypass via memory patching, and operational monetization via a Telegram marketplace; the report includes IOCs (domains, IPs, hashes), technical deobfuscation steps and actionable containment recommendations (isolate, reimage, reset credentials, block IOCs, user education).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.