LummaC Stealer Uses Amadey Bot To Deploy SectopRAT
ID: 0f7998a9-5e98-551c-b851-196c29af5b68
STIX ID: report--0f7998a9-5e98-551c-b851-196c29af5b68
Feed Name: Cyble Blog
This report details a multi-stage malware campaign in which the LummaC stealer (distributed via phishing and fake installers) harvests credentials and downloads the Amadey bot; Amadey persists via copied executables and LNK startup entries and then retrieves and executes SectopRAT, a Themida-packed .NET RAT that steals browser/crypto wallet data and provides remote access. The documentation includes sample hashes, C2 URLs and IPs, MITRE ATT&CK technique mappings, YARA and ET detection rules, and recommended defensive best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
