Multiple incidents have been documented involving the deployment of the Lumma Stealer malware on Windows systems, followed by the installation of additional malicious payloads. Technical analysis reveals that the Lumma Stealer installer, a large PE32 executable, temporarily saves several files to the infected host, including AutoIt3 scripts and various data files. The infection process also generates a custom .a3x AutoIt3 script and establishes command-and-control (C2) communications with domains such as offenms[.]cyou. Network traffic captures and file samples from these incidents have been made available for further analysis, providing insight into the infection chain and the nature of the follow-up malware.
Indicators of compromise (IOCs), packet capture files, and extracted malware samples have been published to assist defenders in identifying and mitigating these threats. The technical details include SHA256 hashes of the malware, file paths used during infection, and specifics about the C2 infrastructure. These resources enable security teams to detect similar infections and understand the tactics used by threat actors leveraging Lumma Stealer in multi-stage attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers documented a Lumma Stealer infection chain in which a password-protected 7-zip archive posing as cracked software delivered an inflated Windows executable padded with null bytes. After the initial Lumma compromise, the infection retrieved and executed Sectop RAT (ArechClient2) as a 64-bit DLL via rundll32, with hashes, delivery URLs, storage paths, and C2 traffic published.
On January 1, 2026, researchers observed another Lumma Stealer infection in which a large PE32 executable dropped multiple files and scripts, including an AutoIt3-based payload, onto a Windows host. The malware communicated with offenms[.]cyou and additional follow-up infrastructure including pastebin[.]com, memory-scanner[.]cc, and communicationfirewall-security[.]cc, with PCAPs and IOCs released for analysis.
A Lumma Stealer infection was observed on December 30, 2025, with evidence that additional follow-up malware was deployed after the initial compromise. Analysis materials including IOCs, PCAP data, and related malware files were made available for defenders and researchers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
isc.sans.edu
Open sourcemalware-traffic-analysis.net
Open sourcemalware-traffic-analysis.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.