From Shadow to Spotlight: The Evolution of LummaStealer and Its Hidden Secrets
ID: 2ce7a2fe-3dbc-5711-88ae-a56446b50aec
STIX ID: report--2ce7a2fe-3dbc-5711-88ae-a56446b50aec
Feed Name: Cybereason Blog
This Cybereason report analyzes LummaStealer — a mature info‑stealer MaaS — detailing a newly observed mshta-based delivery that uses fake CAPTCHA phishing pages, multi-layer obfuscation (HEX/JS → obfuscated PowerShell → AES decryption → XOR/Base64 → in‑memory .NET assembly), AMSI bypass via memory patching, and operational monetization via a Telegram marketplace; the report includes IOCs (domains, IPs, hashes), technical deobfuscation steps and actionable containment recommendations (isolate, reimage, reset credentials, block IOCs, user education).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
