Beware: Fake Browser Updates Deliver BitRAT and Lumma Stealer Malware
ID: 7b98da69-2de4-5df8-ba5d-62f225fc1893
STIX ID: report--7b98da69-2de4-5df8-ba5d-62f225fc1893
Feed Name: The Hacker News
Threat Score
Multiple security vendors observed active campaigns leveraging fake browser update pages and social-engineering to distribute RATs (BitRAT), Lumma Stealer (LummaC2), loaders and PowerShell-based payload chains—using hosting on platforms like Discord, webhards, and pirated-software sites; the activity includes image-hosted payload retrieval, manual PowerShell execution lures (ClearFake), and DNSPod-based fast-flux techniques that increase resilience and scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
