Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

Lumar

Lumar, also referred to as PovertyStealer, is an infostealer malware family. The provided content associates it with theft of Chrome cookies and other browser secrets and states that it successfully bypassed Google Chrome’s App-Bound Encryption (ABE), a protection introduced in Chrome 127 on Windows to better secure cookies and stored credentials. According to the content, Lumar initially addressed ABE with a temporary approach that required the malware to be launched with administrator rights, then later implemented a bypass that worked with the privileges of the logged-in user. The exact technical bypass method is not disclosed in the provided material. The content also places Lumar among multiple stealer families that continued harvesting Chrome data after ABE was introduced.

Operationally, the content describes Lumar as an infostealer used by a traffer team for infections during a broader malware distribution operation active from June 2023 through early September 2023. SpyCloud Labs confirmed the team used Lumar, but reported no public stats panel, campaign spreadsheets, or additional campaign details for this malware family. No specific threat actor attribution beyond that usage context, no industry-specific targeting, and no concrete indicators of compromise are provided in the source material.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1189Drive-by CompromiseEvidence1

In this scheme, victims click a software download button on a site claiming to provide access to a sought-after program, and thereafter are redirected through a variety of websites (many ending in *.click or *.xyz), before eventually being presented with a file to download, which contains the malware.

Execution

1 technique
T1204.002Malicious FileEvidence1

victims click a software download button on a site claiming to provide access to a sought-after program... before eventually being presented with a file to download, which contains the malware.

Privilege Escalation

2 techniques
T1068Exploitation for Privilege EscalationEvidence1

This model does not allow infostealer malware, which runs with the permissions of the logged user, to steal secrets stored in Chrome browser. To bypass this protection, the malware would need system privileges...

T1548.002Bypass User Account ControlEvidence1

Multiple families have successfully bypassed App-Bound Encryption including Phemedrone, LummaC2, Meduza, Vidar, StealC, Rhadamanthys, WhiteSnake, Meta, and Lumar.

Stealth

1 technique
T1036MasqueradingEvidence1

Admin tasked other members of the team with creating multiple malware distribution domains, which all posed as cracked software distributions

Credential Access

3 techniques
T1539Steal Web Session CookieEvidence3

This model does not allow infostealer malware, which runs with the permissions of the logged user, to steal secrets stored in Chrome browser.

T1555.003Credentials from Web BrowsersEvidence1

Новый метод позволяет обходить механизм шифрования с привязкой к приложению (Application-Bound Encryption, ABE) Chrome — механизм для защиты сессионных файлов cookie и другой ценной информации, хранящейся в браузере.

T1649Steal or Forge Authentication CertificatesEvidence1

their only post being about troubleshooting a credential checker that they were using to validate credentials they stole.

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
uri●●●●●●●●●●●●View more in app2 years ago
uri●●●●●●●●●●●●View more in app2 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.