PULSE NAME
Lumma Stealer's GitHub-Based Delivery Explored via Managed Detection and Response
WHITE Stargazer Goblin AlienVault 2025-01-31 Modified: 2025-03-02
36
IOCs
MEDIUM VOLUME
Trend Micro's Managed XDR team investigated a sophisticated campaign distributing Lumma Stealer through GitHub. The attackers exploited GitHub's release infrastructure to deliver various malware, including SectopRAT, Vidar, and Cobeacon. The campaign used compromised websites for redirection to GitHub-hosted malicious payloads. The malware exfiltrated sensitive data, connected to C&C servers, and employed evasion techniques. The tactics show similarities with the Stargazer Goblin group, known for using compromised websites and GitHub for payload distribution. The attack chain involved multiple stages, including initial access through GitHub, execution of malware, and subsequent deployment of additional tools. The campaign highlights the evolving distribution methods of Lumma Stealer and the importance of proactive security measures.
Indicators of Compromise (1 / 36 total)
All URL FileHash-MD5 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 80e7a9318067557b21a24d1906ab3f05a5f250eb63dde4dd8a3335908953a46a 2025-01-31