Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
ID: c3cb7ead-f283-566c-944f-74c743fa56a2
STIX ID: report--c3cb7ead-f283-566c-944f-74c743fa56a2
Feed Name: SANS ISC Diary
Threat Score
This diary documents a Lumma Stealer infection obtained from a cracked-software site using a password-protected archive and an inflated, null-padded EXE, followed by deployment of Sectop RAT. The report includes the sample SHA256, file details, C2 domains discovered via sandboxing, and Sectop RAT C2 IPs/endpoints, illustrating a common cyber-crime distribution technique and providing actionable IOCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
