PULSE NAME
Tracking LummaC2 Infrastructure with Cats
WHITE LummaC2 AlienVault 2025-05-30 Modified: 2025-07-09
130
IOCs
HIGH VOLUME
The US Department of Justice and Microsoft disrupted LummaC2 infostealing-malware through domain seizures, taking down over 2,300 associated domains. The FBI and CISA released an advisory detailing LummaC2's tactics and indicators of compromise, including 114 domains. Analysis of these domains revealed common registration patterns, such as using Eastern European names and specific mail server hostnames. Notably, several domains featured an 'About Cats' landing page, with 58 additional domains sharing this characteristic and having high risk scores. These domains are suspected of distributing LummaC2 and other malware strains. Despite the takedown efforts, 41 of these domains remain active, highlighting the need for continued vigilance against LummaC2 infrastructure.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
LummaC2
Indicators of Compromise (20 / 130 total)
All FileHash-MD5 FileHash-SHA1 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1fc59ff559c941f99cf27c18ef066789 2025-05-30
FileHash-MD5 36a25a0c6dbc42e3b0018a89cf1e5d7c 2025-05-30
FileHash-MD5 45a16d54edb7453c992f898c6085d7aa 2025-05-30
FileHash-MD5 48360d300e9549d09ef0988f1f3e9940 2025-05-30
FileHash-MD5 4d9dd0f2400e4d0484eb7b8245a14521 2025-05-30
FileHash-MD5 552ef4dcb1034387830d1b3d9888433f 2025-05-30
FileHash-MD5 576df09b25a6496eac399155221d159e 2025-05-30
FileHash-MD5 5c931c5129104a1993c22b6a42def5ea 2025-05-30
FileHash-MD5 5e94f3d061bc4339a5eab48ac569b189 2025-05-30
FileHash-MD5 64adca8de7794635841da885aabc33c8 2025-05-30
FileHash-MD5 792ef5f0e22f4740ba354246856258c1 2025-05-30
FileHash-MD5 8413af3e5e4b413dab097ff0debe9750 2025-05-30
FileHash-MD5 90a122f4ea2845708765d641accaedb5 2025-05-30
FileHash-MD5 a920faa21aeb448f9e0a89602c227682 2025-05-30
FileHash-MD5 c03c8572c80443b496f20d11ca9f6c10 2025-05-30
FileHash-MD5 edf65a0c3eb94b3181460ea8fffea76b 2025-05-30
FileHash-MD5 f0f4b6e16b8d4005aec799e41a6c7287 2025-05-30
FileHash-MD5 f516b9050fd743e8b6f89a932acea38f 2025-05-30
FileHash-MD5 f72c2dd8f3e64ee3a70c0af8865e3e3d 2025-05-30
FileHash-MD5 fa43d5ac21544a9bba95e04c7e4bc250 2025-05-30