PULSE NAME
Lumma Stealer's GitHub-Based Delivery Explored via Managed Detection and Response
WHITE Stargazer Goblin AlienVault 2025-01-31 Modified: 2025-03-02
36
IOCs
MEDIUM VOLUME
Trend Micro's Managed XDR team investigated a sophisticated campaign distributing Lumma Stealer through GitHub. The attackers exploited GitHub's release infrastructure to deliver various malware, including SectopRAT, Vidar, and Cobeacon. The campaign used compromised websites for redirection to GitHub-hosted malicious payloads. The malware exfiltrated sensitive data, connected to C&C servers, and employed evasion techniques. The tactics show similarities with the Stargazer Goblin group, known for using compromised websites and GitHub for payload distribution. The attack chain involved multiple stages, including initial access through GitHub, execution of malware, and subsequent deployment of additional tools. The campaign highlights the evolving distribution methods of Lumma Stealer and the importance of proactive security measures.
Indicators of Compromise (36)
All URL FileHash-MD5 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
URL https://kassalias.com 2025-01-31
FileHash-MD5 afdc1a1e1e934f18be28465315704a12 2025-01-31
FileHash-MD5 b2e581c85432bd4df6a59a00cbda1cb3 2025-01-31
FileHash-SHA256 80e7a9318067557b21a24d1906ab3f05a5f250eb63dde4dd8a3335908953a46a 2025-01-31
URL http://192.142.10.246/login.php?event=init&id=cucumber=&data=16 2025-01-31
URL http://84.200.24.26/login.php?event=init&id=underskirt==&data=16 2025-01-31
URL http://91.202.233.18:9000/wbinjget?q=B2E581C85432BD4DF6A59A00CBDA1CB3 2025-01-31
URL http://sacpools.com 2025-01-31
URL https://afterpm.com 2025-01-31
URL https://ageless-skincare.com/gn/ 2025-01-31
URL https://comicshopjocks.com 2025-01-31
URL https://compass-point-yachts.com 2025-01-31
URL https://eaholloway.com 2025-01-31
URL https://enricoborino.com 2025-01-31
URL https://klipcatepiu0.shop/int_clp_sha.txt 2025-01-31
URL https://lakeplacidluxuryhomes.com 2025-01-31
URL https://pmpdm.com 2025-01-31
URL https://primetimeessentials.com 2025-01-31
URL https://razorskigrips.com 2025-01-31
URL https://startherehosting.net 2025-01-31
domain afterpm.com 2025-01-31
domain ageless-skincare.com 2025-01-31
domain comicshopjocks.com 2025-01-31
domain compass-point-yachts.com 2025-01-31
domain eaholloway.com 2025-01-31
domain enricoborino.com 2025-01-31
domain ikores.sbs 2025-01-31
domain kassalias.com 2025-01-31
domain klipcatepiu0.shop 2025-01-31
domain lakeplacidluxuryhomes.com 2025-01-31
domain lumdukekiy.shop 2025-01-31
domain pmpdm.com 2025-01-31
domain primetimeessentials.com 2025-01-31
domain razorskigrips.com 2025-01-31
domain sacpools.com 2025-01-31
domain startherehosting.net 2025-01-31