PULSE NAME
Malware Distributed Using Falcon Sensor Update Phishing Lure
WHITE AlienVault 2024-07-29 Modified: 2024-07-29
36
IOCs
MEDIUM VOLUME
CrowdStrike Intelligence uncovered a phishing campaign impersonating CrowdStrike and distributing malicious files containing a Microsoft Installer (MSI) loader. The loader executes the commodity stealer 'Lumma Stealer' packed with 'CypherIt'. This campaign is likely linked to a previous 'Lumma Stealer' distribution effort leveraging advanced social engineering techniques. The malware evades detection by terminating if security products are detected, and employs multiple layers of obfuscation. It ultimately connects to command and control servers to exfiltrate stolen data.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Lumma Stealer
Indicators of Compromise (2 / 36 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 c98eee5919b9ebe871a116027d40f42f9bf267f8 2024-07-29
FileHash-SHA1 f2f57024c7cc3f9ff5f999ee20c4f5c38bfc20a2 2024-07-29