Lumma Stealer

 



LummaStealer is a Malware-as-a-Service (MaaS) available on the dark web, reflecting a shift in the cyber threat landscape. Unlike traditional methods, this platform enables aspiring threat actors to access sophisticated malware without intricate technical skills. The malware marketplace has evolved, emphasizing user-friendly experiences, ease of use, and ongoing development to outsmart antivirus systems. With LummaStealer and similar services, emerging cybercriminals receive not only professionally crafted malware but also guaranteed troubleshooting and customer support, significantly lowering the entry barrier for malicious activities. This trend highlights the commercialization and accessibility of cyber threats, potentially empowering a broader range of individuals in the realm of cybercrime.

Target OS

  •     Windows 7 to Windows 11, both 32-64 bit, including Server editions.

Infection Vector

Lumma Stealer has been identified employing various distribution tactics, including drive-by-downloads, where unsuspecting users inadvertently download the malware while visiting compromised websites. Additionally, the malware disguises itself as seemingly legitimate browser updates, tricking users into unwittingly installing the malicious software. Moreover, Lumma Stealer is found on deceptive websites that entice users with game downloads and software cracks, exploiting individuals seeking unauthorized access to content. These diverse distribution methods underscore the adaptability and stealth of Lumma Stealer in infiltrating systems through different avenues, making it a multifaceted and potent threat in the cybersecurity landscape.

Identification

  • C2 Communication
    • fanlumpactiras[.]pw 
    • tirechinecarpett[.]pw 
  • Behavior
    • "C:\Users\Admin\AppData\Local\Temp\file.exe"
    • "http[:]//ownerbuffersuperw[.]pw/api"
  • Strings
    • "LummaC2, Build Nov 28 2023, Buy now: TG @lummanowork"
    • "act=recive_message&lid=%s&j=%s&ver=4.0"

MITRE ATT&CK

  • T1129 - Shared Modules
  • T1027 - Obfuscated Files or Information
  • T1083 - File and Directory Discovery
  • T1033 - System Owner/User Discovery
  • T1012 - Query Registry

Evasion techniques

 Lumma Stealer,has adopted a novel evasion technique to outsmart security software. The malware now incorporates a sophisticated strategy that involves measuring mouse movements through trigonometry. This approach helps Lumma Stealer assess whether it is operating on an authentic user's machine or within the confines of an antivirus sandbox environment designed for security analysis. By dynamically analyzing mouse behavior, Lumma stealer attempts to discern the subtle nuances that distinguish real-world user interaction from the more controlled and predictable patterns observed in sandbox environments, thereby enhancing its ability to go undetected by security measures. This tactic showcases the malware's adaptability and the constant cat-and-mouse game between cyber attackers and security systems.

IOC's

  • Hash 
    • 57e79fb736ee84447c19c21f4a5cee53
    • 34f3f70c79b708ff980c53bb08513fae
    • 80a02e784a4ceae734c167bbc6e6f3b3
    • d5b1a5175ca8f2e8640291e4714e6fe8  
  •  C2
    • fanlumpactiras[.]pw
    • tirechinecarpett[.]pw
    • musclefarelongea[.]pw
    • ownerbuffersuperw[.]pw
for more IOC

         


 

Comments