{"id":3242,"date":"2025-06-06T03:51:34","date_gmt":"2025-06-06T03:51:34","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=3242"},"modified":"2025-06-06T03:51:36","modified_gmt":"2025-06-06T03:51:36","slug":"eset-takes-half-in-world-operation-to-disrupt-lumma-stealer","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=3242","title":{"rendered":"ESET takes half in world operation to disrupt Lumma Stealer"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>ESET has collaborated with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/aka.ms\/Lumma-Stealer\" target=\"_blank\" rel=\"noopener\">Microsoft<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bitsight.com\/blog\/lumma-stealer-is-out-of-business\" target=\"_blank\" rel=\"noopener\">BitSight<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.lumen.com\/en-us\/solutions\/connected-security.html\" target=\"_blank\" rel=\"noopener\">Lumen<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cloudflare.com\/\" target=\"_blank\" rel=\"noopener\">Cloudflare<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cleandns.com\/\" target=\"_blank\" rel=\"noopener\">CleanDNS<\/a>, and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.gmoregistry.com\/en\/\" target=\"_blank\" rel=\"noopener\">GMO Registry<\/a> in a worldwide disruption operation in opposition to Lumma Stealer, an notorious malware-as-a-service (MaaS) infostealer. The operation focused Lumma Stealer infrastructure with all recognized C&amp;C servers up to now yr, rendering the exfiltration community, or a big a part of it, nonoperational.<\/p>\n<blockquote>\n<p><strong>Key factors of this blogpost:<\/strong><\/p>\n<ul>\n<li>ESET took half in a coordinated world operation to disrupt Lumma Stealer.<\/li>\n<li>ESET offered technical evaluation and statistical info, and extracted important information from tens of 1000&#8217;s of malware samples.<\/li>\n<li>We offer an outline of the Lumma Stealer MaaS ecosystem.<\/li>\n<li>We additionally present technical evaluation and an outline of the evolution of Lumma Stealer\u2019s key static and dynamic properties, which have been vital to the disruption effort.<\/li>\n<\/ul>\n<\/blockquote>\n<h2>Disruption contribution<\/h2>\n<p>ESET automated techniques processed tens of 1000&#8217;s of Lumma Stealer samples, dissecting them to extract key components, resembling C&amp;C servers and affiliate identifiers. This allowed us to repeatedly monitor Lumma Stealer\u2019s exercise, monitor growth updates, cluster associates, and extra.<\/p>\n<p>Infostealer malware households, like Lumma Stealer, are sometimes only a foreshadowing of a future, way more devastating assault. Harvested credentials are a valued commodity within the cybercrime underground, offered by preliminary entry brokers to varied different cybercriminals, together with ransomware associates. Lumma Stealer has been one of the crucial prevalent infostealers over the previous two years, and ESET telemetry (see Determine 1) confirms that it has left no a part of the world untouched.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-1.png\" alt=\"Figure 1. Lumma Stealer detection rate (data since July 2024)\" width=\"\" height=\"\"\/><figcaption><em>Determine 1. Lumma Stealer detection fee (information since July 2024)<\/em><\/figcaption><\/figure>\n<p>Lumma Stealer builders had been actively creating and sustaining their malware. We have now recurrently observed code updates starting from minor bug fixes to finish alternative of string encryption algorithms and adjustments to the community protocol. The operators additionally actively maintained the shared exfiltration community infrastructure. Between June 17<sup>th<\/sup>, 2024 and Might 1<sup>st<\/sup>, 2025, we noticed a complete of three,353 distinctive C&amp;C domains, averaging roughly 74 new domains rising every week together with occasional updates to Telegram-based dead-drop resolvers (see Determine 2). We focus on the main points of the community infrastructure later within the blogpost.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 2. Weekly counts of new C&amp;C domains\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-2.png\" alt=\"Figure 2. Weekly counts of new C&amp;C domains\" width=\"\" height=\"\"\/><figcaption><em>Determine 2. Weekly counts of latest C&amp;C domains<\/em><\/figcaption><\/figure>\n<p>This ongoing evolution underscores the numerous menace posed by Lumma Stealer and highlights the significance and complexity of the disruption effort.<\/p>\n<h2>Background<\/h2>\n<p>Over the previous two years, Lumma Stealer (often known as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/details\/win.lumma\" target=\"_blank\" rel=\"noopener\">LummaC or LummaC2<\/a>) has emerged as one of the crucial energetic infostealers within the cybercrime ecosystem, changing into a well-liked device amongst cybercriminals resulting from its energetic growth of malware options and its infrastructure being offered as a service.<\/p>\n<h3>Malware as a service<\/h3>\n<p>Lumma Stealer adopts the idea of malware as a service (MaaS), the place associates pay a month-to-month payment, primarily based on their tier, to obtain the most recent malware builds and the community infrastructure needed for information exfiltration. Associates have entry to a administration panel with a user-friendly interface the place they will obtain exfiltrated information and harvested credentials.<\/p>\n<p>The tiered subscription mannequin ranges from USD 250 to USD 1,000 per thirty days, every with more and more subtle options. Decrease tiers embrace fundamental filtering and log obtain choices, whereas greater tiers supply customized information assortment, evasion instruments, and early entry to new options. The costliest plan emphasizes stealth and flexibility, providing distinctive construct technology and decreased detection.<\/p>\n<p>The operators of Lumma Stealer have additionally created a Telegram market with a score system for associates to promote stolen information with out intermediaries. {The marketplace} has been nicely documented in Cybereason <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cybereason.com\/blog\/threat-analysis-lummastealer-2.0#:~:text=Monetization%20without%20intermediaries\" target=\"_blank\" rel=\"noopener\">analysis<\/a>. Furthermore, they preserve public documentation of the administration panel for associates and periodically share updates and fixes on hacking boards, as proven in Determine 3.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 3. The official Lumma Stealer documentation \u2013 machine translated from Russian to English (May 12th, 2025)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-3.png\" alt=\"Figure 3. The official LummaStealer documentation \u2013 machine translated from Russian to English\" width=\"\" height=\"\"\/><figcaption><em>Determine 3. The official Lumma Stealer documentation \u2013 machine translated from Russian to English (Might 12<sup>th<\/sup>, 2025)<\/em><\/figcaption><\/figure>\n<p>Open documentation not solely helps associates with much less expertise to make use of the malware service, but additionally supplies precious insights for safety researchers. Builders deal with malware builds, information pipelining, and infrastructure upkeep, whereas associates are chargeable for distributing the malware. This info, mixed with the service\u2019s reputation, ends in all kinds of compromise vectors.<\/p>\n<p>Frequent distribution strategies embrace phishing, cracked software program, and different malware downloaders together with SmokeLoader, DarkGate, Amadey, Vidar, and others. Standard phishing schemes contain <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.proofpoint.com\/uk\/blog\/threat-insight\/security-brief-clickfix-social-engineering-technique-floods-threat-landscape\" target=\"_blank\" rel=\"noopener\">ClickFix<\/a> or <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.gdatasoftware.com\/blog\/2025\/03\/38154-lummastealer-fake-recaptcha\" target=\"_blank\" rel=\"noopener\">pretend CAPTCHA<\/a> internet pages, fraudulent boards with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cybereason.com\/blog\/threat-analysis-rise-of-lummastealer#:~:text=Fake%20CAPTCHA%20Challenge-,Initial%20Infection,-While%20each%20individual\" target=\"_blank\" rel=\"noopener\">cracked software program<\/a>, pretend <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/25\/c\/ai-assisted-fake-github-repositories.html\" target=\"_blank\" rel=\"noopener\">GitHub repositories<\/a>, fraudulent hyperlinks on Reddit boards, and lots of extra.<\/p>\n<h2>Technical evaluation<\/h2>\n<p>Quite a few public analyses have already been written about Lumma Stealer and its compromise vectors. Our focus right here, nonetheless, is on the points related to the disruption. On this part, we are going to briefly introduce the important thing static and dynamic properties that we&#8217;ve got been actively extracting from Lumma Stealer.<\/p>\n<h3>Static properties of Lumma Stealer<\/h3>\n<p>Numerous info comes embedded in Lumma Stealer malware samples. This naturally presents a really perfect goal for automated extraction. In addition to the plain information of curiosity \u2013 C&amp;C server domains \u2013 the samples additionally include identifier strings that tie the pattern to a selected affiliate and a marketing campaign, and an optionally available identifier resulting in a customized dynamic configuration. These identifiers are utilized in community communication with the C&amp;C server throughout information exfiltration and requests for dynamic configuration. Within the sections beneath, we take a look at these properties in depth.<\/p>\n<h4>C&amp;C domains<\/h4>\n<p>Every Lumma Stealer pattern comprises a listing of 9 encrypted C&amp;C domains. Whereas the encryption strategies have developed over time, the attribute array construction has remained constant as much as the time of writing.<\/p>\n<p>Primarily based on Lumma Stealer\u2019s inner pattern versioning, which is closely protected by stack string obfuscation, we all know that up till January 2025, the C&amp;C domains within the samples have been protected by an XOR perform and base64 encoding (see Determine 4). When the base64-encoded string was decoded, it revealed a construction the place the primary 32 bytes served as an XOR key, and the remaining bytes contained the encrypted C&amp;C area.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 4. List of XOR-protected and base64-encoded C&amp;C domains\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-4.png\" alt=\"Figure 4. List of XOR-protected and base64-encoded C&amp;C domains\" width=\"\" height=\"\"\/><figcaption><em>Determine 4. Record of XOR-protected and base64-encoded C&amp;C domains<\/em><\/figcaption><\/figure>\n<p>In January 2025, Lumma Stealer transitioned the safety of the C&amp;C record to ChaCha20 encryption with a single hardcoded key and nonce (see Determine 5). This safety of the C&amp;C record within the Lumma Stealer binaries has remained the identical up till the time of publication.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 5. ChaCha20-protected C&amp;C domains\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-5.png\" alt=\"Figure 5. ChaCha20-protected C&amp;C domains\" width=\"\" height=\"\"\/><figcaption><em>Determine 5. ChaCha20-protected C&amp;C domains<\/em><\/figcaption><\/figure>\n<h4>Useless-drop resolvers<\/h4>\n<p>Since June 2024, every Lumma Stealer construct got here with a brand new function for acquiring a backup C&amp;C. If no C&amp;C server from the static config responds to Lumma Stealer, then the backup C&amp;C is extracted from a dummy Steam profile internet web page performing as a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1102\/001\/\" target=\"_blank\" rel=\"noopener\">dead-drop resolver<\/a>. The Steam profile URL is closely protected within the binary, the identical approach because the model string. The encrypted backup C&amp;C URL is about within the Steam profile identify, as proven in Determine 6, and the safety is a straightforward <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Caesar_cipher\" target=\"_blank\" rel=\"noopener\">Caesar cipher<\/a> (ROT11).<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 6. Steam profile and Telegram channel used as dead-drop resolvers\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-6.png\" alt=\"Figure 6. Steam profile and Telegram channel used as dead-drop resolvers\" width=\"\" height=\"\"\/><figcaption><em>Determine 6. Steam profile and Telegram channel used as dead-drop resolvers<\/em><\/figcaption><\/figure>\n<p>In February 2025, Lumma Stealer acquired an replace that included a function for acquiring a brand new, main C&amp;C URL from a Telegram channel dead-drop resolver. The C&amp;C URL is extracted from the Telegram channel\u2019s title area, and it&#8217;s protected by the identical algorithm as within the case of the Steam profile dead-drop resolver. The primary distinction within the utilization of the Telegram and Steam profile dead-drop resolvers is that the Telegram possibility is examined first, whereas the Steam profile is used as a final resort if profitable communication has not been established with beforehand obtained C&amp;C servers (Determine 16).<\/p>\n<p>Furthermore, we consider that the Telegram dead-drop resolver is on the market for greater tier subscriptions. It is because many samples should not have the Telegram URL set, and subsequently the malware skips this technique.<\/p>\n<h4>Lumma Stealer identifier<\/h4>\n<p>Every Lumma Stealer pattern comprises a singular hardcoded affiliate identifier often known as LID. It&#8217;s embedded in plaintext kind and utilized for communication with C&amp;C servers. Up till March 2025, the LID parameter string adopted a structured format, delimited by two dashes (Determine 7). A\u00a0detailed evaluation of the LID affiliate string is offered in an upcoming part.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 7. LID identifier in Lumma Stealer sample\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-7.png\" alt=\"Figure 7. LID identifier in LummaStealer sample\" width=\"\" height=\"\"\/><figcaption><em>Determine 7. LID identifier in Lumma Stealer pattern<\/em><\/figcaption><\/figure>\n<p>Though essentially the most prevalent LID noticed throughout our monitoring begins with the string <span style=\"font-family: courier new, courier, monospace;\">uz4s1o<\/span>; the second commonest LID, which begins with <span style=\"font-family: courier new, courier, monospace;\">LPnhqo<\/span>, supplies a greater instance for visualizing typical LID variability. Within the phrase cloud in Determine 8, we current the highest 200 LIDs collected throughout our monitoring, beginning with <span style=\"font-family: courier new, courier, monospace;\">LPnhqo<\/span>.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 8. List of the top 200 LID identifiers beginning with the LPnhqo prefix seen in our telemetry\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-8.png\" alt=\"Figure 8. List of the top 200 LID identifiers beginning with the LPnhqo prefix seen in our telemetry\" width=\"\" height=\"\"\/><figcaption><em>Determine 8. Record of the highest 200 LID identifiers starting with the<\/em> <span style=\"font-family: courier new, courier, monospace;\">LPnhqo<\/span><em> prefix seen in our telemetry<\/em><\/figcaption><\/figure>\n<p>Nevertheless, in early March 2025, Lumma Stealer transitioned to utilizing hexadecimal identifiers, referred to internally as UID (see Determine 9).<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 9. Comparison of HTTPS POST requests for a dynamic configuration\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-9.png\" alt=\"Figure 9. Dynamic configuration HTTPS POST request comparison\" width=\"\" height=\"\"\/><figcaption><em>Determine 9. Comparability of HTTPS POST requests for a dynamic configuration<\/em><\/figcaption><\/figure>\n<h4>Non-obligatory configuration identifier<\/h4>\n<p>Along with the LID parameter, Lumma Stealer samples can also include an optionally available parameter referred to internally as J. When current, this parameter is in cleartext and formatted as a 32-byte ASCII hex string (see Determine 10). The J parameter is utilized within the C&amp;C request for dynamic configuration with extra definitions for exfiltration. We speak about dynamic configuration in additional element in a following part.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 10. The J parameter in a Lumma Stealer sample\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-10.png\" alt=\"Figure 10. J parameter in the LummaStealer sample\" width=\"\" height=\"\"\/><figcaption><em>Determine 10. The J parameter in a Lumma Stealer pattern<\/em><\/figcaption><\/figure>\n<p>If the J parameter is lacking within the Lumma Stealer pattern, an empty string is used within the C&amp;C request and a default configuration is retrieved. Not like LID, the J parameter is never current in Lumma Stealer samples. Nevertheless, it performs an important function when current, because it allows retrieving a dynamic configuration that considerably will increase the stealer\u2019s capabilities, making it a extra versatile exfiltration device for menace actors.<\/p>\n<p>In March 2025, when the LID parameter was renamed to UID and its format modified, the J parameter was renamed to CID however with no change to its format or perform.<\/p>\n<h3>Evaluation of static properties<\/h3>\n<p>From our long-term monitoring and statistical evaluation of LID parameters, we consider that the primary phase of the LID identifies the affiliate, whereas the second phase differentiates between campaigns. Primarily based on this assumption you&#8217;ll be able to see the highest 200 affiliate identifiers in Determine 11.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 11. The most frequently seen affiliate identifiers in our telemetry\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-11.png\" alt=\"Figure 11. The most frequently seen affiliate identifiers in our telemetry\" width=\"\" height=\"\"\/><figcaption><em>Determine 11. Essentially the most steadily seen affiliate identifiers in our telemetry<\/em><\/figcaption><\/figure>\n<p>Furthermore, we&#8217;ve got been in a position to create a visualization of the associates\u2019 actions over the previous yr (see Determine 12). This visualization highlights every week in January 2025. Most of these visualizations have offered us with precious insights into the patterns and behaviors of various menace actors. Moreover, the visualizations reveal a shared, domain-based C&amp;C infrastructure amongst most Lumma Stealer associates. On the identical time, we have been in a position to determine much less steadily used C&amp;C domains, which we suspect have been reserved for greater tier associates or extra necessary campaigns.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 12. Visualization of Lumma Stealer infrastructure utilization (early January 2025 time frame)\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-12.png\" alt=\"Figure 12. Visualization of LummaStealer infrastructure utilization (early January 2025 time frame)\" width=\"\" height=\"\"\/><figcaption><em>Determine 12. Visualization of Lumma Stealer infrastructure utilization (early January 2025 time-frame)<\/em><\/figcaption><\/figure>\n<h3>Dynamic properties of Lumma Stealer<\/h3>\n<p>Lumma Stealer retrieves a dynamic configuration from the C&amp;C server, which comprises definitions specifying what to scan for exfiltration (see Desk 1). The first focus is on stealing internet browser extension information and databases containing passwords, session cookies, internet looking historical past, and autofill information. In addition to internet browsers, it additionally focuses on stealing information from password managers, VPNs, FTP purchasers, cloud providers, distant desktop purposes, electronic mail purchasers, cryptocurrency wallets, and note-taking purposes.<\/p>\n<p style=\"break-after: avoid; text-align: center;\"><em>Desk 1. Dynamic config\u2019s JSON fields<\/em><\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"160\"><strong>Key<\/strong><\/td>\n<td width=\"630\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"222\"><span style=\"font-family: courier new, courier, monospace;\">v<\/span><\/td>\n<td width=\"399\">Dynamic config model.<\/td>\n<\/tr>\n<tr>\n<td width=\"222\"><span style=\"font-family: courier new, courier, monospace;\">se<\/span><\/td>\n<td width=\"399\">Possibility for taking a screenshot of the sufferer\u2019s machine for exfiltration.<\/td>\n<\/tr>\n<tr>\n<td width=\"222\"><span style=\"font-family: courier new, courier, monospace;\">ex<\/span><\/td>\n<td width=\"399\">Record of Chromium-based browser extensions to focus on for exfiltration.<br \/>Every entry consists of:<br \/>\u00a0\u00b7\u00a0 The extension ID, saved as <span style=\"font-family: courier new, courier, monospace;\">en<\/span>.<br \/>\u00a0\u00b7 \u00a0The extension identify, saved as <span style=\"font-family: courier new, courier, monospace;\">ez<\/span>.<\/td>\n<\/tr>\n<tr>\n<td width=\"222\"><span style=\"font-family: courier new, courier, monospace;\">c<\/span><\/td>\n<td width=\"399\">Definition of recordsdata focused for exfiltration. <br \/>Essentially the most attention-grabbing entries are:<br \/>\u00a0\u00b7\u00a0 The trail for file scanning, saved as <span style=\"font-family: courier new, courier, monospace;\">p<\/span>.<br \/>\u00a0\u00b7\u00a0 The file extension record filter for exfiltration, saved as <span style=\"font-family: courier new, courier, monospace;\">m<\/span>.<br \/>\u00a0\u00b7\u00a0 The utmost folder scanning depth, saved as <span style=\"font-family: courier new, courier, monospace;\">d<\/span>.<br \/>\u00a0\u00b7\u00a0 The utmost file measurement for exfiltration, saved as <span style=\"font-family: courier new, courier, monospace;\">fs<\/span>.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Despite the fact that we haven\u2019t seen vital adjustments within the default configurations, this function enhances the malware\u2019s potential to carry out focused exfiltration (see Determine 13). A complete overview of the configuration fields has already been nicely documented on this <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/spycloud.com\/blog\/reversing-lummac2\/#:~:text=LummaC2%20Config%20Analysis\" target=\"_blank\" rel=\"noopener\">analysis<\/a> by SpyCloud.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 13. Example of a dynamic config\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-13.png\" alt=\"Figure 13. Example of a dynamic config\" width=\"\" height=\"\"\/><figcaption><em>Determine 13. Instance of a dynamic config<\/em><\/figcaption><\/figure>\n<p>The configuration is in JSON format, and it&#8217;s downloaded from the C&amp;C server utilizing an HTTPS POST request that features the LID identifier, optionally available J parameter, and a selected hardcoded Person-Agent string.<\/p>\n<p>The safety of the dynamic configuration has modified a number of instances not too long ago. Previously, it was protected in the identical approach because the static C&amp;C record, by a 32-byte XOR perform and base64 encoding. In March 2025 the safety modified to ChaCha20, the place the important thing and nonce have been prepended to the encrypted configuration.<\/p>\n<p>The Person-Agent string is necessary to observe, as offering it accurately is important for receiving the dynamic configuration. In April 2025, Lumma Stealer launched an extra layer of obfuscation by encrypting JSON values utilizing an 8-byte XOR perform (see Determine 14).<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 14. Dynamic configuration with encryption of some values\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-14.png\" alt=\"Figure 14. Dynamic configuration with encryption of some values\" width=\"\" height=\"\"\/><figcaption><em>Determine 14. Dynamic configuration with encryption of some values<\/em><\/figcaption><\/figure>\n<p>This encrypted variant of the dynamic configuration is delivered when a barely up to date Person-Agent string is specified (see Desk 2).<\/p>\n<p style=\"break-after: avoid; text-align: center;\"><em>Desk 2. Person-Agent variants<\/em><\/p>\n<table style=\"width: 100%;\" border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td style=\"width: 50%;\" width=\"390\"><strong>Person-Agent<\/strong><\/td>\n<td style=\"width: 50%;\" width=\"390\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 50%;\" width=\"222\"><span style=\"font-family: courier new, courier, monospace;\">Mozilla\/5.0 (Home windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/1<span style=\"font-family: Consolas, monospace; background-color: #0096a1; color: white;\">1<\/span>9.0.0.0 Safari\/537.36<\/span><\/td>\n<td style=\"width: 50%;\" width=\"399\">Previous Person-Agent string leading to a dynamic configuration variant proven in Determine 13.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%;\" width=\"222\"><span style=\"font-family: courier new, courier, monospace;\">Mozilla\/5.0 (Home windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/1<span style=\"font-family: Consolas, monospace; background-color: #0096a1; color: white;\">0<\/span>9.0.0.0 Safari\/537.36<\/span><\/td>\n<td style=\"width: 50%;\" width=\"399\">New Person-Agent string leading to a dynamic configuration variant with encryption of some values (Determine 14).<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>In addition to this dynamic configuration method, Lumma Stealer samples nonetheless include hardcoded directions for exfiltrating recordsdata. These embrace information from purposes resembling Outlook or Thunderbird, Steam account info, and Discord account tokens (see <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/spycloud.com\/blog\/lummac2-malware-stealthier-capabilities\" target=\"_blank\" rel=\"noopener\">this SpyCloud blogpost<\/a>). This mixture of dynamic and hardcoded configurations ensures that Lumma Stealer can successfully acquire a variety of precious information.<\/p>\n<p>To summarize all of the static and dynamic adjustments talked about to date, we&#8217;ve got created a timeline (Determine 15) highlighting essentially the most vital developments noticed within the Lumma Stealer malware over the previous yr.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 15. Timeline of the most significant updates over the past year\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-15.png\" alt=\"Figure 15. Timeline of the most significant updates over the past year\" width=\"\" height=\"\"\/><figcaption><em>Determine 15. Timeline of essentially the most vital updates over the previous yr<\/em><\/figcaption><\/figure>\n<h3>C&amp;C communication<\/h3>\n<p>All through our Lumma Stealer monitoring interval, all extracted C&amp;C domains persistently led to Cloudflare providers, that are utilized to hide Lumma Stealer\u2019s actual C&amp;C infrastructure. Cloudflare providers are additionally employed for C&amp;C servers positioned by way of dead-drop resolvers.<\/p>\n<p>First, Lumma Stealer must get hold of an energetic C&amp;C server. The mechanism of this alternative is illustrated within the move chart proven in Determine 16.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 16. C&amp;C selection mechanism\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-16.png\" alt=\"Figure 16. C&amp;C selection mechanism\" width=\"\" height=\"\"\/><figcaption><em>Determine 16. C&amp;C choice mechanism<\/em><\/figcaption><\/figure>\n<h4>Handshake<\/h4>\n<p>Though the precise handshake request to the C&amp;C server shouldn&#8217;t be current within the newest Lumma Stealer builds, it&#8217;s price mentioning as a result of it was a function of our monitoring for a very long time. The handshake request was an HTTPS POST request containing <span style=\"font-family: courier new, courier, monospace;\">act=dwell<\/span> and a hardcoded Person-Agent. Energetic servers responded with a cleartext <span style=\"font-family: courier new, courier, monospace;\">okay<\/span> message.<\/p>\n<h4>Configuration request<\/h4>\n<p>When Lumma Stealer identifies an energetic C&amp;C server, it requests the configuration by way of an HTTPS POST request (Determine 17), which incorporates the LID and J parameters as information. If the J parameter shouldn&#8217;t be current within the pattern, Lumma Stealer retrieves the default configuration from the C&amp;C server. This configuration specifies what to scan for exfiltration, permitting the malware to adapt to completely different targets and environments.<\/p>\n<h4>Extra payload execution<\/h4>\n<p>After Lumma Stealer efficiently exfiltrates delicate information and harvested credentials, it points one ultimate HTTPS POST request to the C&amp;C server \u2013 this time, with an extra sufferer {hardware} ID referred to as <span style=\"font-family: courier new, courier, monospace;\">hwid<\/span>. This ultimate request retrieves a configuration of an extra payload to be executed on the sufferer\u2019s machine. The payload or a URL to obtain from is a part of that configuration. Observe that such a payload shouldn&#8217;t be all the time offered.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 17. Lumma Stealer C&amp;C communication flow\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-17.png\" alt=\"Figure 17. LummaStealer C&amp;C communication flow\" width=\"\" height=\"\"\/><figcaption><em>Determine 17. Lumma Stealer C&amp;C communication move<\/em><\/figcaption><\/figure>\n<h3>Anti-analysis obfuscation strategies<\/h3>\n<p>Lumma Stealer employs a number of, however efficient, anti-emulation strategies to make evaluation as difficult as attainable. These strategies are designed to evade detection and hinder the efforts of safety analysts.<\/p>\n<h4>Oblique soar obfuscation<\/h4>\n<p>One of many main obfuscation strategies utilized by Lumma Stealer is oblique management move flattening, proven in Determine 18. This technique successfully disrupts the code blocks of the features, making it almost unimaginable to maintain monitor of the perform logic. By flattening the management move, the malware obfuscates its operations, complicating the evaluation course of. For an in depth exploration of this method and thorough evaluation of those obfuscation patterns, together with an overview of the answer, you&#8217;ll be able to confer with this complete <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/lummac2-obfuscation-through-indirect-control-flow\" target=\"_blank\" rel=\"noopener\">article<\/a> by Mandiant.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 18. Indirect control flow obfuscation\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-18.png\" alt=\"Figure 18. Indirect control flow obfuscation\" width=\"\" height=\"\"\/><figcaption><em>Determine 18. Oblique management move obfuscation<\/em><\/figcaption><\/figure>\n<h4>Stack strings<\/h4>\n<p style=\"page-break-after: avoid;\">One other approach employed by Lumma Stealer is using encrypted stack strings, as illustrated in Determine 19. This technique successfully hides binary information and lots of necessary strings within the Lumma Stealer pattern, making static evaluation of the binary tough. Furthermore, every encrypted string has its personal distinctive mathematical perform for decryption, including one other layer of complexity to the evaluation course of.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 19. Stack string decryption routine\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-19.png\" alt=\"Figure 19. Stack string decryption routine\" width=\"\" height=\"\"\/><figcaption><em>Determine 19. Stack string decryption routine<\/em><\/figcaption><\/figure>\n<h4>Import API obfuscation<\/h4>\n<p style=\"page-break-after: avoid;\">In Lumma Stealer, imports are resolved at runtime. Import names are hashed utilizing the FNV-1a algorithm with every construct utilizing a customized offset foundation. As proven in Determine 20, since August 25<sup>th<\/sup>, 2024, Lumma Stealer additionally obfuscates the FNV hash algorithm parameters through the use of stack strings.<\/p>\n<figure class=\"image\"><img decoding=\"async\" title=\"Figure 20. Stack string obfuscation of hash parameters used for obfuscating imported API names\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2025\/05-25\/lumma-stealer\/figure-20.png\" alt=\"Figure 20. Import API hash algorithm parameter obfuscation\" width=\"\" height=\"\"\/><figcaption><em>Determine 20. Stack string obfuscation of hash parameters used for obfuscating imported API names<\/em><\/figcaption><\/figure>\n<h2>Conclusion<\/h2>\n<p>This world disruption operation was made attainable by our long-term monitoring of Lumma Stealer, which we&#8217;ve got offered an outline of on this blogpost. We have now described the modus operandi of the Lumma Stealer group and its service. Moreover, we&#8217;ve got documented the necessary static identifiers and C&amp;C communication in addition to its evolution over the past yr. Lastly, we summarized the important thing obfuscation strategies that make the evaluation of Lumma Stealer difficult.<\/p>\n<p>The disruption operation, led by Microsoft, goals to grab all recognized Lumma Stealer C&amp;C domains, rendering Lumma Stealer\u2019s exfiltration infrastructure nonfunctional. ESET will proceed to trace different infostealers whereas intently monitoring for Lumma Stealer exercise following this disruption operation.<\/p>\n<blockquote>\n<div><em>For any inquiries about our analysis revealed on WeLiveSecurity, please contact us at <a rel=\"nofollow\" target=\"_blank\" style=\"background-color: #f4f4f4;\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/eset-takes-part-global-operation-disrupt-lumma-stealer\/mailto:threatintel@eset.com?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=autotagging&amp;utm_content=eset-research&amp;utm_term=en\">threatintel@eset.com<\/a>.\u00a0<\/em><\/div>\n<div><em>ESET Analysis gives non-public APT intelligence stories and information feeds. For any inquiries about this service, go to the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=eset-takes-part-global-operation-disrupt-lumma-stealer&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\">ESET Menace Intelligence<\/a> web page.<\/em><\/div>\n<\/blockquote>\n<h2>IoCs<\/h2>\n<h3><span style=\"font-size: medium; font-weight: 400;\"><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"179\"><strong>SHA-1<\/strong><\/td>\n<td width=\"132\"><strong>Filename<\/strong><\/td>\n<td width=\"170\"><strong>Detection<\/strong><\/td>\n<td width=\"161\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">6F94CFAABB19491F2B8E<wbr\/>719D74AD032D4BEB3F29<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">AcroRd32.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2024-06-27.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">C5D3278284666863D758<wbr\/>7F1B31B06F407C592AC4<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">Notion.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2024-07-14.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">5FA1EDC42ABB42D54D98<wbr\/>FEE0D282DA453E200E99<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">explorer.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2024-08-08.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">0D744811CF41606DEB41<wbr\/>596119EC7615FFEB0355<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">aspnet_regiis<wbr\/>.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2024-08-25.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">2E3D4C2A7C68DE2DD31A<wbr\/>8E0043D9CF7E7E20FDE1<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">nslookup.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2024-09-20.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">09734D99A278B3CF59FE<wbr\/>82E96EE3019067AF2AC5<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">nslookup.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2024-10-04.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">1435D389C72A5855A5D6<wbr\/>655D6299B4D7E78A0127<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">BitLockerToGo<wbr\/>.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2024-11-09.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">2CCCEA9E1990D6BC7755<wbr\/>CE5C3B9B0E4C9A8F0B59<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">exterior.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2024-12-23.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">658550E697D9499DB782<wbr\/>1CBBBF59FFD39EB59053<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">Wemod-Premium-Unlocker-2025<\/span><\/td>\n<td width=\"170\">MSIL\/GenKryptik.HGWU<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2025-01-18.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">070A001AC12139CC1238<wbr\/>017D795A2B43AC52770D<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">khykuQw.exe<\/span><\/td>\n<td width=\"170\">Win32\/Kryptik.HYUC<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2025-02-27.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">1FD806B1A0425340704F<wbr\/>435CBF916B748801A387<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">Begin.exe<\/span><\/td>\n<td width=\"170\">Win64\/Injector.WR<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2025-03-24.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">F4840C887CAAFF0D5E07<wbr\/>3600AEC7C96099E32030<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">loader.exe<\/span><\/td>\n<td width=\"170\">Win64\/Kryptik.FAZ<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2025-04-15.<\/td>\n<\/tr>\n<tr>\n<td width=\"179\"><span style=\"font-family: courier new, courier, monospace;\">8F58C4A16717176DFE3C<wbr\/>D531C7E41BEF8CDF6CFE<\/span><\/td>\n<td width=\"132\"><span style=\"font-family: courier new, courier, monospace;\">Set-up.exe<\/span><\/td>\n<td width=\"170\">Win32\/Spy.Lumma Stealer.B<\/td>\n<td width=\"161\">Lumma Stealer pattern \u2013 Construct 2025-04-23.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/span><\/h3>\n<h3>Community<\/h3>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"151\"><strong>IP<\/strong><\/td>\n<td width=\"180\"><strong>Area<\/strong><\/td>\n<td width=\"104\"><strong>Internet hosting supplier<\/strong><\/td>\n<td width=\"79\"><strong>First seen<\/strong><\/td>\n<td width=\"129\"><strong>Particulars<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.134[.]100<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">cooperatvassquaidmew[.]xyz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.175[.]165<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">crisisrottenyjs[.]xyz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.96[.]1<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">deadtrainingactioniw[.]xyz<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">tamedgeesy[.]sbs<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">nighetwhisper[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.141[.]43<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">exuberanttjdkwo[.]xyz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.96[.]3<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">grandcommonyktsju[.]xyz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.92[.]96<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">qualificationjdwko[.]xyz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.209[.]200<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">sweetcalcutangkdow[.]xyz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.49[.]80<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">wordingnatturedowo[.]xyz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.97[.]0<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">bigmouthudiop[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">froytnewqowv[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">locatedblsoqp[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">stagedchheiqwo[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201116<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.19[.]156<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">callosallsaospz[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201118<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.153[.]40<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">indexterityszcoxp[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201118<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.192[.]52<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">lariatedzugspd[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201118<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.213[.]85<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">liernessfornicsa[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201118<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.137[.]78<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">outpointsozp[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201118<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.221[.]214<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">shepherdlyopzc[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201118<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.204[.]158<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">unseaffarignsk[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201118<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.178[.]194<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">upknittsoappz[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201107\u201118<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.97[.]3<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">bassizcellskz[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">byteplusx[.]digital<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">sparkiob[.]digital<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">longitudde[.]digital<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201107<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.47[.]141<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">celebratioopz[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201107<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.158[.]159<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">complaintsipzzx[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201107<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.204[.]20<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">deallerospfosu[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201107<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.35[.]48<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">languagedscie[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201107<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.73[.]43<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">mennyudosirso[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201107<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.97[.]9<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">quialitsuzoxm[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201107<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.166[.]231<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">writerospzm[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201107<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.16[.]180<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">caffegclasiqwp[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201124<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.146[.]35<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">condedqpwqm[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201124<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">N\/A<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">evoliutwoqm[.]store<\/span><\/td>\n<td width=\"104\">N\/A<\/td>\n<td width=\"79\">2024\u201108\u201124<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.96[.]0<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">millyscroqwp[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">stamppreewntnq[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">advennture[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201124<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.67[.]155<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">traineiwnqo[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201108\u201124<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">94.140.14[.]33<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">achievenmtynwjq[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">carrtychaintnyw[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">chickerkuso[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">metallygaricwo[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">milldymarskwom[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">opponnentduei[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">puredoffustow[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">quotamkdsdqo[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">bemuzzeki[.]sbs<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">exemplarou[.]sbs<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">exilepolsiy[.]sbs<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">frizzettei[.]sbs<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">invinjurhey[.]sbs<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">isoplethui[.]sbs<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">laddyirekyi[.]sbs<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">wickedneatr[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201109\u201121<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.97[.]4<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">usseorganizedw[.]store<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">bellflamre[.]click on<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">tripfflux[.]world<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201109\u201124<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.44[.]84<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">beerishint[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201110\u201106<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.64[.]84<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">1212tank.activitydmy[.]icu<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201111\u201112<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.93[.]246<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">brownieyuz[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201111\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.189[.]210<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">ducksringjk[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201111\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.146[.]64<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">explainvees[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201111\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.90[.]226<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">relalingj[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201111\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.14[.]17<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">repostebhu[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201111\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.192[.]43<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">rottieud[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201111\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.97[.]1<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">thinkyyokej[.]sbs<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201111\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.97[.]7<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">bashfulacid[.]lat<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">tentabatte[.]lat<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201112\u201123<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.86[.]54<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">curverpluch[.]lat<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201112\u201123<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.66[.]86<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">lev\u2011tolstoi[.]com<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201112\u201117<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.64.80[.]1<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">manyrestro[.]lat<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">toppyneedus[.]biz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201112\u201123<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.97[.]2<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">shapestickyr[.]lat<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201112\u201123<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.192[.]247<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">slipperyloo[.]lat<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201112\u201123<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.105.90[.]131<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">steamcommunity[.]com<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">steamcommunity[.]com<\/span><\/td>\n<td width=\"104\">Akamai Applied sciences, Inc.<\/td>\n<td width=\"79\">2024\u201106\u201127<\/td>\n<td width=\"129\">Steam profile useless\u2011drop resolvers.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.146[.]68<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">talkynicer[.]lat<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201112\u201123<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.184[.]241<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">wordyfindy[.]lat<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2024\u201112\u201123<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">N\/A<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">beevasyeip[.]bond<\/span><\/td>\n<td width=\"104\">N\/A<\/td>\n<td width=\"79\">2025\u201101\u201122<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">N\/A<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">broadecatez[.]bond<\/span><\/td>\n<td width=\"104\">N\/A<\/td>\n<td width=\"79\">2025\u201101\u201122<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">N\/A<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">encirelk[.]cyou<\/span><\/td>\n<td width=\"104\">N\/A<\/td>\n<td width=\"79\">2025\u201101\u201128<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">N\/A<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">granystearr[.]bond<\/span><\/td>\n<td width=\"104\">N\/A<\/td>\n<td width=\"79\">2025\u201101\u201122<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">N\/A<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">quarrelepek[.]bond<\/span><\/td>\n<td width=\"104\">N\/A<\/td>\n<td width=\"79\">2025\u201101\u201122<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">N\/A<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">rockemineu[.]bond<\/span><\/td>\n<td width=\"104\">N\/A<\/td>\n<td width=\"79\">2025\u201101\u201128<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.19[.]91<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">suggestyuoz[.]biz<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201101\u201122<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">N\/A<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">tranuqlekper[.]bond<\/span><\/td>\n<td width=\"104\">N\/A<\/td>\n<td width=\"79\">2025\u201101\u201122<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.69[.]194<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">codxefusion[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201102\u201128<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.80[.]1<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">earthsymphzony[.]right this moment<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">climatologfy[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201102\u201126<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.88[.]16<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">experimentalideas[.]right this moment<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201101<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.146[.]181<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">gadgethgfub[.]icu<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201101<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.48[.]238<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">hardrwarehaven[.]run<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201102\u201128<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.16[.]1<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">hardswarehub[.]right this moment<\/span><br \/><span style=\"font-family: courier new, courier, monospace;\">pixtreev[.]run<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201102\u201128<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.39[.]95<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">quietswtreams[.]life<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201102\u201126<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.222[.]46<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">socialsscesforum[.]icu<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201103<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.191[.]187<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">techmindzs[.]dwell<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201101<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.214[.]226<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">techspherxe[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201101<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.26[.]124<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">appgridn[.]dwell<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201124<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.178[.]7<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">lunoxorn[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201131<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.47[.]117<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">skynetxc[.]dwell<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201124<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.72[.]121<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">targett[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201120<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">188.114.96[.]2<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">travewlio[.]store<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201103\u201120<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.42[.]7<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">changeaie[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.85[.]126<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">clarmodq[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.161[.]40<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">liftally[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.176[.]107<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">piratetwrath[.]run<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201117<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.215[.]114<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">quilltayle[.]dwell<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201117<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.143[.]12<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">salaccgfa[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.5[.]146<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">starofliught[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201117<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.32[.]1<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">zestmodp[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201108<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.147[.]123<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">equatorf[.]run<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201121<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.112[.]1<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">hemispherexz[.]high<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201121<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">104.21.20[.]106<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">latitudert[.]dwell<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201121<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"151\"><span style=\"font-family: courier new, courier, monospace;\">172.67.216[.]12<\/span><\/td>\n<td width=\"180\"><span style=\"font-family: courier new, courier, monospace;\">sectorecoo[.]dwell<\/span><\/td>\n<td width=\"104\">Cloudflare, Inc.<\/td>\n<td width=\"79\">2025\u201104\u201119<\/td>\n<td width=\"129\">Lumma Stealer C&amp;C server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>MITRE ATT&amp;CK strategies<\/h2>\n<p>This desk was constructed utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/resources\/versions\/\">model 17<\/a> of the MITRE ATT&amp;CK framework<strong>.<\/strong><\/p>\n<table border=\"1\" width=\"642\" cellspacing=\"0\" cellpadding=\"0\">\n<thead>\n<tr>\n<td width=\"113\"><strong>Tactic<\/strong><\/td>\n<td width=\"113\"><strong>ID<\/strong><\/td>\n<td width=\"151\"><strong>Title<\/strong><\/td>\n<td width=\"265\"><strong>Description<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td rowspan=\"3\" width=\"113\"><strong>Useful resource Improvement<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1587\/001\" target=\"_blank\" rel=\"noopener\">T1587.001<\/a><\/td>\n<td width=\"151\">Develop Capabilities: Malware<\/td>\n<td width=\"265\">Lumma Stealer operators actively developed their malware as a product for his or her service.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1583\/001\" target=\"_blank\" rel=\"noopener\">T1583.001<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure: Domains<\/td>\n<td width=\"265\">Lumma Stealer operators registered domains for his or her exfiltration infrastructure.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1583\/006\" target=\"_blank\" rel=\"noopener\">T1583.006<\/a><\/td>\n<td width=\"151\">Purchase Infrastructure: Net Companies<\/td>\n<td width=\"265\">Lumma Stealer operators used Cloudflare providers to cover their infrastructure. Lumma Stealer additionally hid its C&amp;C URLs in public providers like dummy Steam profiles or empty Telegram channels.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Execution<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1059\/003\" target=\"_blank\" rel=\"noopener\">T1059.003<\/a><\/td>\n<td width=\"151\">Command-Line Interface: Home windows Command Shell<\/td>\n<td width=\"265\">Lumma Stealer executes <span style=\"font-family: courier new, courier, monospace;\">cmd.exe<\/span> to delete non permanent recordsdata.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1106\" target=\"_blank\" rel=\"noopener\">T1106<\/a><\/td>\n<td width=\"151\">Native API<\/td>\n<td width=\"265\">Lumma Stealer executes a wide range of Home windows APIs, together with <span style=\"font-family: courier new, courier, monospace;\">VirtualAlloc<\/span>, <span style=\"font-family: courier new, courier, monospace;\">LoadLibraryA<\/span>, and <span style=\"font-family: courier new, courier, monospace;\">GetProcAddress<\/span>.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1204\/001\" target=\"_blank\" rel=\"noopener\">T1204.001<\/a><\/td>\n<td width=\"151\">Person Execution: Malicious Hyperlink<\/td>\n<td width=\"265\">Lumma Stealer operators supply a easy LNK packing function for his or her malware builds.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1047\" target=\"_blank\" rel=\"noopener\">T1047<\/a><\/td>\n<td width=\"151\">Home windows Administration Instrumentation<\/td>\n<td width=\"265\">Lumma Stealer makes use of WMI queries to collect system info.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Protection Evasion<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1622\" target=\"_blank\" rel=\"noopener\">T1622<\/a><\/td>\n<td width=\"151\">Debugger Evasion<\/td>\n<td width=\"265\">Lumma Stealer checks for debugger presence.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1140\" target=\"_blank\" rel=\"noopener\">T1140<\/a><\/td>\n<td width=\"151\">Deobfuscate\/Decode Recordsdata or Info<\/td>\n<td width=\"265\">Lumma Stealer makes use of ChaCha20 for C&amp;C record and dynamic config encryption.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1027\/007\" target=\"_blank\" rel=\"noopener\">T1027.007<\/a><\/td>\n<td width=\"151\">Obfuscated Recordsdata or Info: Dynamic API Decision<\/td>\n<td width=\"265\">Lumma Stealer resolves API names at runtime utilizing the FNV-1a hash algorithm.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1027\/013\" target=\"_blank\" rel=\"noopener\">T1027.013<\/a><\/td>\n<td width=\"151\">Obfuscated Recordsdata or Info: Encrypted\/Encoded File<\/td>\n<td width=\"265\">Lumma Stealer encrypts strings and necessary binary information utilizing stack strings or ChaCha20.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Credential Entry<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1555\/003\" target=\"_blank\" rel=\"noopener\">T1555.003<\/a><\/td>\n<td width=\"151\">Credentials from Password Shops: Credentials from Net Browsers<\/td>\n<td width=\"265\">Lumma Stealer gathers credentials from a number of browsers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1539\" target=\"_blank\" rel=\"noopener\">T1539<\/a><\/td>\n<td width=\"151\">Steal Net Session Cookie<\/td>\n<td width=\"265\">Lumma Stealer gathers cookies from a number of browsers.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"6\" width=\"113\"><strong>Discovery<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1217\" target=\"_blank\" rel=\"noopener\">T1217<\/a><\/td>\n<td width=\"151\">Browser Bookmark Discovery<\/td>\n<td width=\"265\">Lumma Stealer checks and collects varied details about put in browsers on victims\u2019 machines.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1012\" target=\"_blank\" rel=\"noopener\">T1012<\/a><\/td>\n<td width=\"151\">Question Registry<\/td>\n<td width=\"265\">Lumma Stealer queries registry keys to record put in software program on victims\u2019 machines.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1057\" target=\"_blank\" rel=\"noopener\">T1057<\/a><\/td>\n<td width=\"151\">Course of Discovery<\/td>\n<td width=\"265\">Lumma Stealer sends the method record to its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1518\" target=\"_blank\" rel=\"noopener\">T1518<\/a><\/td>\n<td width=\"151\">Software program Discovery<\/td>\n<td width=\"265\">Lumma Stealer sends a listing of put in software program to its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1082\" target=\"_blank\" rel=\"noopener\">T1082<\/a><\/td>\n<td width=\"151\">System Info Discovery<\/td>\n<td width=\"265\">Lumma Stealer sends system info to its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1124\" target=\"_blank\" rel=\"noopener\">T1124<\/a><\/td>\n<td width=\"151\">System Time Discovery<\/td>\n<td width=\"265\">Lumma Stealer sends the present system time and time zone to its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"4\" width=\"113\"><strong>Assortment<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1560\" target=\"_blank\" rel=\"noopener\">T1560<\/a><\/td>\n<td width=\"151\">Archive Collected Information<\/td>\n<td width=\"265\">Lumma Stealer compresses gathered information earlier than exfiltration to its C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1119\" target=\"_blank\" rel=\"noopener\">T1119<\/a><\/td>\n<td width=\"151\">Automated Assortment<\/td>\n<td width=\"265\">Lumma Stealer&#8217;s exfiltration capabilities are absolutely automated and primarily based on a configuration file.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1113\" target=\"_blank\" rel=\"noopener\">T1113<\/a><\/td>\n<td width=\"151\">Display Seize<\/td>\n<td width=\"265\">Lumma Stealer takes screenshots of victims\u2019 machines primarily based on dynamic configuration.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1005\" target=\"_blank\" rel=\"noopener\">T1005<\/a><\/td>\n<td width=\"151\">Information from Native System<\/td>\n<td width=\"265\">Lumma Stealer collects native system information from victims\u2019 machines.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"5\" width=\"113\"><strong>Command and Management<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1071\/001\" target=\"_blank\" rel=\"noopener\">T1071.001<\/a><\/td>\n<td width=\"151\">Software Layer Protocol: Net Protocols<\/td>\n<td width=\"265\">Lumma Stealer makes use of HTTPS communication with its C&amp;C servers.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1132\/001\" target=\"_blank\" rel=\"noopener\">T1132.001<\/a><\/td>\n<td width=\"151\">Information Encoding: Normal Encoding<\/td>\n<td width=\"265\">Lumma Stealer used base64 encoding for acquiring its configuration from the C&amp;C server.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1573\/001\" target=\"_blank\" rel=\"noopener\">T1573.001<\/a><\/td>\n<td width=\"151\">Encrypted Channel: Symmetric Cryptography<\/td>\n<td width=\"265\">Lumma Stealer makes use of extra ChaCha20 encryption below the HTTPS community protocol.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1008\" target=\"_blank\" rel=\"noopener\">T1008<\/a><\/td>\n<td width=\"151\">Fallback Channels<\/td>\n<td width=\"265\">Lumma Stealer employs backup dead-drop resolvers in Steam profiles and Telegram channels.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1102\/001\" target=\"_blank\" rel=\"noopener\">T1102.001<\/a><\/td>\n<td width=\"151\">Net Service: Useless Drop Resolver<\/td>\n<td width=\"265\">Lumma Stealer employs backup dead-drop resolvers in Steam profiles and Telegram channels.<\/td>\n<\/tr>\n<tr>\n<td rowspan=\"2\" width=\"113\"><strong>Exfiltration<\/strong><\/td>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1020 target=\" rel=\"noopener\">T1020<\/a><\/td>\n<td width=\"151\">Automated Exfiltration<\/td>\n<td width=\"265\">Lumma Stealer exfiltrates stolen credentials and information over the C&amp;C channel.<\/td>\n<\/tr>\n<tr>\n<td width=\"113\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/attack.mitre.org\/versions\/v17\/techniques\/T1041\" target=\"_blank\" rel=\"noopener\">T1041<\/a><\/td>\n<td width=\"151\">Exfiltration Over C2 Channel<\/td>\n<td width=\"265\">Lumma Stealer exfiltrates stolen credentials and information over the C&amp;C channel.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=eset-takes-part-global-operation-disrupt-lumma-stealer&amp;sfdccampaignid=7011n0000017htTAAQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/eti-eset-threat-intelligence.png\" alt=\"\" width=\"915\" height=\"296\"\/><\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>ESET has collaborated with Microsoft, BitSight, Lumen, Cloudflare, CleanDNS, and GMO Registry in a worldwide disruption operation in opposition to Lumma Stealer, an notorious malware-as-a-service (MaaS) infostealer. The operation focused Lumma Stealer infrastructure with all recognized C&amp;C servers up to now yr, rendering the exfiltration community, or a big a part of it, nonoperational. Key [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3244,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[3080,679,3079,2255,2130,668,2256,595],"class_list":["post-3242","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-disrupt","tag-eset","tag-global","tag-lumma","tag-operation","tag-part","tag-stealer","tag-takes"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3242","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3242"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3242\/revisions"}],"predecessor-version":[{"id":3243,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3242\/revisions\/3243"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/3244"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3242"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3242"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3242"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-27 10:07:07 UTC -->