LummaC2 Stealer
Key findings
In this report are presented:
Lumma Stealer, also known as LummaC2 Stealer, is a malware-as-a-service sold through Telegram and Russian-speaking cybercrime forums. In this report, the following will be addressed:
- The presence of Lumma in Russian-speaking forums and Telegram.
- Code analysis of different campaigns distributing Lumma stealer using various techniques.
- The infrastructure associated with Lumma stealer, including the old and new versions of C2 panels.A trail, that we uncovered, which indicates a potential use of Lumma by a Russian intrusion set.
Intrinsec’s CTI services
Organisations are facing a rise in the sophistication of threat actors and intrusion sets. To address these evolving threats, it is now necessary to take a proactive approach in the detection and analysis of any element deemed malicious. Such a hands-on approach allows companies to anticipate, or at least react as quickly as possible to the compromises they face.
For this report, shared with our clients in July 2023, Intrinsec relied on its Cyber Threat Intelligence service, which provides its customers with high value-added, contextualized and actionable intelligence to understand and contain cyber threats. Our CTI team consolidates data & information gathered from our security monitoring services (SOC, MDR …), our incident response team (CERT-Intrinsec) and custom cyber intelligence generated by our analysts using custom heuristics, honeypots, hunting, reverse-engineering & pivots.
Intrinsec also offers various services around Cyber Threat Intelligence:
- Risk anticipation: which can be leveraged to continuously adapt the detection & response capabilities of our clients’ existing tools (EDR, XDR, SIEM, …) through:
- an operational feed of IOCs based on our exclusive activities.
- threat intel notes & reports, TIP-compliant.
- Digital risk monitoring:
- data leak detection & remediation
- external asset security monitoring (EASM)
- brand protection
For more information, go to www.intrinsec.com/en/cyber-threat-intelligence/.
Other analysis
Ongoing threats targeting the energy industry
Cyber Threats targetting the energy industry GuLoader Information reportKey findings In this report are presented: The origin of the malware and...
Cybercrime Threat Landscape August 2023
Here is a retrospective of the major trends observed by Intrinsec's Cyber Threat Intelligence team regarding the month of August 2023. This...
Cybercrime Threat Landscape May 2023
Here is a retrospective of the major trends observed by Intrinsec's Cyber Threat Intelligence team regarding the month of May 2023. This cybercrime...
ALPHV ransomware gang analysis
ALPHV (or BlackCat or Noberus) ransomware emerged only last December and is already considered as a genuine...
N'hésitez pas à nous contacter
Laissez-nous un message décrivant vos besoins en sécurité, ou bien contactez-nous si vous souhaitez avoir des informations concernant nos activités. Nous vous répondrons dans les meilleurs délais.
N’oubliez pas de renseigner votre adresse e-mail ou téléphone afin que nous puissions vous recontacter rapidement.