logo

Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain, (Wed, Jan 14th)

ID: 8806b9ae-e3c3-5d6e-bfa6-bd3ed7206d12

STIX ID: report--8806b9ae-e3c3-5d6e-bfa6-bd3ed7206d12

Feed Name: SANS ISC Diary

Threat Score
65/100

Date Published: 2026-01-14

Date Updated: 2026-04-19

...
...

This diary documents a Lumma Stealer infection observed on 2026-01-14 where, after data exfiltration, the host retrieves a Pastebin-hosted PowerShell command (https://pastebin.com/raw/xRmmdinT) that executes content from fileless-market.cc via mshta. The follow-up activity creates numerous scheduled tasks that repeatedly execute the same mshta call, producing sustained HTTPS C2 traffic (dozens of TCP streams) to fileless-market.cc, and the report includes relevant IOCs and screenshots of traffic and the Task Scheduler.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.