Lumma Infostealer is a Windows-focused information-stealing malware family used to harvest browser credentials, email data, and cryptocurrency wallet information from infected systems. It is commonly associated with financially motivated cybercrime activity and has been observed in active exploitation chains that abuse client-side software vulnerabilities to deliver payloads and establish persistence.
Observed Lumma delivery activity includes malicious RAR archives exploiting CVE-2025-8088 in WinRAR on Windows. In these campaigns, crafted archives abuse Alternate Data Streams and path traversal behavior during extraction to place malicious components into locations that execute at user logon, enabling persistence. Reported infection chains include a first-stage executable that retrieves additional payloads from attacker-controlled infrastructure, as well as variants that use startup scripts, PowerShell-based retrieval of dependencies, and DLL side-loading as part of execution and evasion.
The malware’s primary role is credential and data theft rather than destructive action. Reported targeting includes end-user systems from which browser-stored secrets, email-related data, and wallet material can be collected. Lumma has also been prominent enough to become the subject of coordinated disruption activity, including infrastructure seizure operations involving U.S. and European authorities and Microsoft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw. | Lumma Infostealer Variant The Lumma Infostealer group is actively exploiting a WinRAR vulnerability to steal browser credentials, email data, and wallet information from users.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
strings refer to creating scheduled task with the name of servicedata4 and running just one
the decoded command I have found opens a shortened URL that hosts some commands and then parses the content of it and then executes it with PowerShell
The VBScript initiates the PowerShell process and retrieves the next stage PowerShell script. The PowerShell script downloads the next stage payload from the attackers C2 server.
mshta.exe is used to directly download and run a remote Visual Basic Script (Inter.odd) hosted on the attacker’s C2 server.
Instead of calling high-level Windows APIs... the loader uses direct syscalls to perform sensitive memory operations.
strings refer to creating scheduled task with the name of servicedata4 and running just one
the campaign instead injected shellcode directly into the process thread.
This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
This multi-stage, heavily obfuscated approach highlights how infostealers continue to evolve with sophisticated evasion and loader techniques
the campaign instead injected shellcode directly into the process thread.
The second stage creates a new, suspended instance of DllHost process. It then injects the decrypted third-stage payload into this process using user-mode Asynchronous Procedure Call (APC) injection
The embedded third-stage payload is decrypted using the BCryptDecrypt API.
we can find how much the threat actor relies on signed legitimate binaries to evade detection
the user is immediately presented with a fake CAPTCHA verification instructions. The instructions trick the user into performing a specific sequence of clicks that ultimately spawn the MSHTA process and executes a malicious script.
The payload actively scans the infected machine for various indicators that could reveal the presence of a debugging tools, or sandboxed environment(Ex: machine configurations, graphics/display adapters etc).
It then actively searches for the following debugging tools/ Virtual machine processes by enumerating running processes and matching names/hashes.
'tasklist' 와 'findstr' 명령을 사용하여 아래 목록에 해당하는 보안 프로세스가 실행 중인지 확인합니다.
ChromElevator targets Chromium-based browsers (such as Chrome, Edge, and Brave). The tool exfiltrates browser cookies, passwords, payment information, autofill data, and potentially OAuth tokens
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer malware referenced in the newsletter roundup; typically associated with credential and data theft.
An infostealer used in exploitation of the WinRAR flaw to steal browser credentials, email data, and cryptocurrency wallet information.
Lumma Infostealer is a malware designed to steal sensitive information such as credentials and other data from infected systems. Its infrastructure was recently seized in a coordinated law enforcement operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.