PULSE NAME
Your Data Is Under New Management: The Rise of LummaStealer
WHITE AlienVault 2024-12-18 Modified: 2025-01-17
36
IOCs
MEDIUM VOLUME
LummaStealer, a relatively new information-stealing malware, has gained prominence since 2022 for its ability to collect sensitive data from Windows systems. Marketed as Malware-as-a-Service (MaaS) on underground forums, it targets individuals, cryptocurrency users, and small to medium-sized businesses. The malware employs various infection vectors, including phishing emails, cracked software, and malicious downloads. It harvests credentials, cookies, cryptocurrency wallets, and system information, exfiltrating data to remote servers. Recent campaigns have shown increased sophistication in social engineering tactics and the use of legitimate platforms like Steam and Dropbox to evade detection. The malware's accessibility through MaaS has made it popular among diverse threat actors, complicating attribution efforts.
Indicators of Compromise (7 / 36 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 3e35a7a3203cc7726ce4e9f7f30806ef 2024-12-18
FileHash-MD5 3f58a517f1f4796225137e7659ad2adb 2024-12-18
FileHash-MD5 477264c48dbbc071190a6c7fc22cbb9c 2024-12-18
FileHash-MD5 4b7f5578a6189b71b5f2d81f30a948f4 2024-12-18
FileHash-MD5 870feaab725b148208dd12ffabe33f9d 2024-12-18
FileHash-MD5 cbf6c2a14cba45f95569c9d011219518 2024-12-18
FileHash-MD5 e74b1e485e42e8ba7a65ab6927e872a5 2024-12-18