Threat actors distributed LummaStealer through two social-engineering chains that targeted users seeking pirated software or attempting to pass fake verification prompts. One campaign, active since at least December 2024, used GitHub repositories, cracked-software forums, URL shorteners, and posts on platforms including Facebook, Devpost, TikTok, and Chromium issues to push victims toward malicious JavaScript. That script suppressed referrer leakage, captured page-title context, and redirected users through intermediary domains on .cfd, .click, .info, and .xyz before serving password-protected archives from MEGA that extracted a LummaStealer executable.
A separate delivery chain used counterfeit CAPTCHA pages to trick users into opening the Windows Run dialog and pasting a PowerShell command that fetched follow-on instructions from a shortened URL, downloaded a ZIP archive from vultrcdn[.]com, and launched a disguised Setup.exe. The infection sequence relied on legitimate-looking or signed binaries such as a revoked Mergecap.exe, a renamed BtDaemon.exe as StrCmp.exe, more.com, and searchindexer.exe, indicating DLL sideloading and process injection for evasion. Investigators observed outbound traffic to suspicious domains including accentypastedw[.]store and onefreex.com, while analysis of the final payload showed infostealer behavior including scheduled task creation, cryptographic API use, timestamp tampering, and file-permission changes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In May 2025, law enforcement, Microsoft, and private-sector partners disrupted infrastructure associated with the Lumma infostealer operation. The action targeted Lumma's malware-as-a-service ecosystem rather than a specific phishing or cracked-software delivery campaign.
Analysis of the cracked-software LummaStealer campaign found the operators also promoted lures through Facebook groups, Devpost, TikTok, Chromium issues, and other platforms. The activity shared several TTPs with Stargazer Goblin and the Stargazers Ghost Network, though attribution remained uncertain.
A malware campaign active since at least December 2024 distributed LummaStealer by posing as cracked software. It used GitHub repositories, URL shorteners, cracked-software forums, malicious JavaScript redirects, intermediary domains, and MEGA-hosted password-protected archives to deliver the payload.
A phishing campaign used fake CAPTCHA pages to trick users into running a PowerShell command via Win+R and Ctrl+V, which then downloaded and launched Lumma Infostealer through a multi-stage chain using legitimate-looking binaries and likely DLL sideloading/process injection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcemedium.com
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.