PayDay Loader is a Windows malware loader reported in the context of the “Dark Partners” operation. It is used as a conduit to deliver Lumma Stealer onto Windows machines. PayDay Loader relies on Google Calendar links as a dead-drop resolver to extract command-and-control (C2) server information and to retrieve obfuscated JavaScript code that is engineered to load the Lumma Stealer payload. Reporting also indicates PayDay Loader includes a Node.js stealer module focused on exfiltrating cryptocurrency wallet data; it uses the ADM-ZIP library to package wallet information and send it to an external C2, with the destination described as a hard-coded C2 host. An associated observable mentioned in reporting is the Google account email address “echeverridelfin@gmail[.]com,” used to create Google Calendar events and also linked to a malicious npm package named “os-info-checker-es6.”
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...a loader dubbed PayDay Loader, which then acts as a conduit for Lumma Stealer on Windows machines."
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows loader that uses Google Calendar links as a dead-drop resolver to retrieve C2 details and obfuscated JavaScript that loads Lumma Stealer; includes a Node.js stealer module to exfiltrate cryptocurrency wallet data (using ADM-ZIP) to a hard-coded C2.
Windows loader (Dark Partners) that uses Google Calendar links as a dead-drop resolver to obtain C2 details and retrieve obfuscated JavaScript that loads Lumma Stealer; also includes a Node.js stealer module to exfiltrate cryptocurrency wallet data (using ADM-ZIP) to a hard-coded C2.
Windows loader that uses Google Calendar as a dead-drop to resolve C2 and fetch obfuscated JavaScript to load Lumma Stealer; also includes a Node.js module to collect and exfiltrate cryptocurrency wallet data (using ADM-ZIP to package data) to a hard-coded C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.