PULSE NAME
Malware Distributed Using Falcon Sensor Update Phishing Lure
WHITE AlienVault 2024-07-29 Modified: 2024-07-29
36
IOCs
MEDIUM VOLUME
CrowdStrike Intelligence uncovered a phishing campaign impersonating CrowdStrike and distributing malicious files containing a Microsoft Installer (MSI) loader. The loader executes the commodity stealer 'Lumma Stealer' packed with 'CypherIt'. This campaign is likely linked to a previous 'Lumma Stealer' distribution effort leveraging advanced social engineering techniques. The malware evades detection by terminating if security products are detected, and employs multiple layers of obfuscation. It ultimately connects to command and control servers to exfiltrate stolen data.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Lumma Stealer
Indicators of Compromise (2 / 36 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 6ee7ddebff0a2b78c7ac30f6e00d1d11 2024-07-29
FileHash-MD5 8a9baf0bf2ffabd39007a630a430a29b 2024-07-29