PULSE NAME
Lumma Stealer's GitHub-Based Delivery Explored via Managed Detection and Response
WHITE Stargazer Goblin AlienVault 2025-01-31 Modified: 2025-03-02
36
IOCs
MEDIUM VOLUME
Trend Micro's Managed XDR team investigated a sophisticated campaign distributing Lumma Stealer through GitHub. The attackers exploited GitHub's release infrastructure to deliver various malware, including SectopRAT, Vidar, and Cobeacon. The campaign used compromised websites for redirection to GitHub-hosted malicious payloads. The malware exfiltrated sensitive data, connected to C&C servers, and employed evasion techniques. The tactics show similarities with the Stargazer Goblin group, known for using compromised websites and GitHub for payload distribution. The attack chain involved multiple stages, including initial access through GitHub, execution of malware, and subsequent deployment of additional tools. The campaign highlights the evolving distribution methods of Lumma Stealer and the importance of proactive security measures.
Indicators of Compromise (2 / 36 total)
All URL FileHash-MD5 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 afdc1a1e1e934f18be28465315704a12 2025-01-31
FileHash-MD5 b2e581c85432bd4df6a59a00cbda1cb3 2025-01-31