● 0 online
ANALYZING THREAT INTELLIGENCE
CTI
PORTAL
Threat Intelligence
INTELLIGENCE
Dashboard
IOC Search
Bulk Search
Pulses
Actors
Tags
Watchlist
ANALYSIS
Phishing
Knowledge Base
SYSTEM
Cache
← Back to Pulse Feed
PULSE
DETAIL
PULSE NAME
IOC - Unmasking The 64-bit Variant of the Infamous Lumma Stealer
WHITE
Lumma Stealer
celestre
2026-04-09
Modified: 2026-04-09
89
IOCs
HIGH VOLUME
↓ CSV
↓ JSON
★ Watch
lumma stealer
application-bound encryption bypass
blockchain c2
tenzor
etherhiding
infostealer
64-bit variant
remus
aurastealer
voidstealer
rhadamanthys
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
T1055
T1027
T1082
T1055.002
T1005
T1497.001
T1573
T1102
T1106
T1134.001
T1555.003
T1555
T1539
T1027.002
T1071.001
T1497
T1185
T1140
T1564.003
MALWARE FAMILIES
Tenzor
Lumma Stealer
Remus
Rhadamanthys
AuraStealer
VoidStealer
Indicators of Compromise (31 / 89 total)
All
FileHash-SHA1
FileHash-SHA256
IPv4
URL
domain
⎘ Copy All
TYPE
INDICATOR
DESCRIPTION
CREATED
URL
http://adveryx.biz:6573
—
2026-04-09
⎘
URL
http://backbou.biz:5902
—
2026-04-09
⎘
URL
http://baxe.pics:48261
—
2026-04-09
⎘
URL
http://borscer.biz:9592
—
2026-04-09
⎘
URL
http://buccstanor.pics:28313
—
2026-04-09
⎘
URL
http://buccstanor.pics:48261
—
2026-04-09
⎘
URL
http://chalx.live:5902
—
2026-04-09
⎘
URL
http://chromap.biz:4219
—
2026-04-09
⎘
URL
http://coox.live:28313
—
2026-04-09
⎘
URL
http://drymoge.biz:4192
—
2026-04-09
⎘
URL
http://forestoaker.com:6290
—
2026-04-09
⎘
URL
http://gluckcreek.online:48261
—
2026-04-09
⎘
URL
http://intem.lat:9592
—
2026-04-09
⎘
URL
http://interxo.biz:7481
—
2026-04-09
⎘
URL
http://josegza.biz:8521
—
2026-04-09
⎘
URL
http://krondez.com:28982
—
2026-04-09
⎘
URL
http://lazzo.bet:3989
—
2026-04-09
⎘
URL
http://managew.biz:5902
—
2026-04-09
⎘
URL
http://navelum.biz:3201
—
2026-04-09
⎘
URL
http://nitroca.biz:6782
—
2026-04-09
⎘
URL
http://outcrol.biz:4895
—
2026-04-09
⎘
URL
http://padaz.pics:4219
—
2026-04-09
⎘
URL
http://parky.pics:3989
—
2026-04-09
⎘
URL
http://prickaz.biz:2039
—
2026-04-09
⎘
URL
http://remnane.biz:5692
—
2026-04-09
⎘
URL
http://ropea.top:28313
—
2026-04-09
⎘
URL
http://siltsoh.biz:7481
—
2026-04-09
⎘
URL
http://texakgi.cloud:3849
—
2026-04-09
⎘
URL
http://vinte.online:28313
—
2026-04-09
⎘
URL
http://woodena.biz:7821
—
2026-04-09
⎘
URL
http://zadno.run:4219
—
2026-04-09
⎘
References (1)
↗ https://www.gendigital.com/blog/insights/research/remus-64bit-variant-of-lumma-stealer