logo

LummaStealer Is Getting a Second Life Alongside CastleLoader

ID: b9f2d23d-e8dd-5f12-9c8e-585feb06185e

STIX ID: report--b9f2d23d-e8dd-5f12-9c8e-585feb06185e

Feed Name: Bitdefender Labs

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-27

Author: Bogdan Ionut Lazar

...
...

**Executive summary:** Bitdefender researchers report a resurgence of the LummaStealer infostealer distributed at scale via CastleLoader and social-engineering lures (fake cracked software, torrents, and ClickFix fake-CAPTCHA pages); the analysis details loader internals (AutoIt variants, in-memory execution, XOR/LZNT1 payload decoding), persistence mechanisms, an anomalous DNS lookup artifact useful for detection, geographic spread, extensive IoCs, and practical user/organizational mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.