Lumma
Author: Infinit3i & Deej1721
Start Date: 2022-08
Most Recent Activity: 2025-03-19
Executive Summary
LummaStealer, also known as LummaC2, is an information stealer offered through a malware-as-a-service model on Russian-speaking forums since at least August 2022. It is commonly delivered through phishing, fake CAPTCHA lures, malicious links, and staged payload chains. The primary impact is the theft and exfiltration of user credentials and other sensitive data to attacker-controlled command and control infrastructure.
Overview
Description
Type: Infostealer / Malware-as-a-Service
Delivery:
Phishing emails, phishing links, fake CAPTCHA pages, malicious downloads, staged follow-on payloads
Capabilities:
Credential theft, data staging, exfiltration, remote access enablement, file upload and execution, anti-analysis behavior
Notable Characteristics:
LummaStealer is commonly associated with multi-stage delivery chains and is often paired with loaders or memory-only payloads such as Peaklight. It is frequently observed in fake CAPTCHA and social engineering campaigns and is designed to collect and exfiltrate user and system data.
Attack Flow
Flow
Nmap → Email → Phishing Link → RDP → File Upload → Run Python Script (Data Staging) → Exfiltration → Remove Files
- Adversary performs reconnaissance or host discovery
- Phishing email or lure is delivered to the victim
- Victim follows a phishing link or fake CAPTCHA workflow
- Remote access or follow-on access is established through RDP or related means
- Malicious files are uploaded to the target environment
- Python or follow-on script is executed for staging collected data
- Stolen data is exfiltrated to attacker-controlled infrastructure
- Files or artifacts are removed to reduce forensic visibility
MITRE ATT&CK Techniques
MITRE ATT&CK
- T1595.002 – Active Scanning
- T1566.001 – Spearphishing Attachment
- T1566.002 – Spearphishing Link
- T1021.001 – Remote Services - Remote Desktop Protocol
- T1105 – Ingress Tool Transfer
- T1074.001 – Data Staged - Local Data Staging
- T1048.002 – Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1070.004 – File Deletion
- T1204.002 – User Execution - Malicious File
- T1115 – Clipboard Data
- T1112 – Modify Registry
- T1010 – Application Window Discovery
- T1012 – Query Registry
- T1129 – Shared Modules
- T1497.001 – Virtualization/Sandbox Evasion
- T1055.003 – Process Injection - Thread Execution Hijacking
- T1027 – Obfuscated Files or Information
- T1140 – Deobfuscate/Decode Files or Information
- T0882 – File and Directory Discovery
Mitigations
Mitigations
- Endpoint Detection and Response: Implement advanced EDR with behavior-based detections and sandboxing for internet-downloaded executables
- Multi-Factor Authentication: Enforce MFA across local, domain, default, and cloud accounts to reduce the value of stolen credentials
- Security Awareness Training: Conduct regular training on phishing, fake CAPTCHA lures, and social engineering techniques
- Email Security: Deploy robust email filtering to block phishing messages and malicious attachments
- Execution Control: Apply strict software execution policies to block fake installers and unauthorized payload execution
- Application Whitelisting: Allow only legitimate applications and scripts, including controls around mshta.exe abuse
- Firewall and Egress Policy: Restrict or monitor outbound connections over ports 80 and 443 for suspicious processes such as mshta.exe where operationally feasible
- IOC Blocking: Block known indicators of compromise from trusted intelligence sources
- Conditional Access: Block logins from non-compliant devices or unauthorized geographies and IP ranges
- Credential Hygiene: Eliminate default credentials, reduce password reuse, rotate SSH keys where applicable, and enforce strong credential policy
- Account Auditing: Routinely audit domain and local accounts and permissions for unauthorized privileged access paths
- Data Loss Prevention: Use DLP controls to detect and block sensitive data uploads through browsers and web services
- Web Proxy Enforcement: Enforce external communication policy through proxies to prevent use of unauthorized services
- Network Intrusion Detection and Prevention: Use network signatures and anomaly detection to identify adversary malware traffic and suspicious exfiltration patterns
Detections
Indicators of Compromise (IOCs)
Detection Rules
| Rule | View | Download |
|---|---|---|
| YARA | N/A | N/A |
| Sigma | N/A | N/A |
| Suricata | N/A | N/A |
| SPL | N/A | N/A |
Research & References
References
- https://securelist.com/angry-likho-apt-attacks-with-lumma-stealer/115663/
- https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware/
- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/behind-the-captcha-a-clever-gateway-of-malware/
- https://denwp.com/dissecting-lumma-malware/
- https://www.rapid7.com/blog/post/2024/08/12/ongoing-social-engineering-campaign-refreshes-payloads/
- https://www.fortinet.com/blog/threat-research/exploiting-cve-2024-21412-stealer-campaign-unleashed
- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/clickfix-deception-a-social-engineering-tactic-to-deploy-malware/
- https://0xmrmagnezi.github.io/malware%20analysis/LummaStealer/
- https://github.com/bgd-cirt/LummaStealer-YARA-Rules/blob/main/README.md
- https://github.com/SEKOIA-IO/Community/blob/main/IOCs/stealc/yara_rules/infostealer_stealc_standalone.yar
- https://www.0x1c.zip/0001-lummastealer/
- https://www.trellix.com/blogs/research/how-attackers-repackaged-a-threat-into-something-that-looked-benign/
- https://www.proofpoint.com/us/blog/threat-insight/clipboard-compromise-powershell-self-pwn
- https://www.virustotal.com/gui/collection/0d487b996555e03ea2853d24c805a473822fafd7da683ab2123d0f1e688001b8
- https://www.esentire.com/blog/fake-browser-updates-delivering-bitrat-and-lumma-stealer
- https://www.fortinet.com/blog/threat-research/lumma-variant-on-youtube
- https://outpost24.com/blog/lummac2-anti-sandbox-technique-trigonometry-human-detection/
- https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks
- https://www.esentire.com/blog/the-case-of-lummac2-v4-0
- https://www.darktrace.com/blog/the-rise-of-the-lumma-info-stealer
- https://any.run/malware-trends/lumma/
- https://any.run/malware-trends/redline
