Researchers documented multiple Lumma Stealer infection chains that begin with fake CAPTCHA or verification pages and trick Windows users into launching malicious PowerShell from the Run dialog. In one case, victims reached the lure through malicious pop-up ads on a pirated-content site; in another, a page at you-checked.com copied a hidden command to the clipboard that fetched follow-on payloads from domains including ferrydero.com and fill-tomap.com. The malware family, also known as LummaC2, is a malware-as-a-service infostealer designed to steal browser data, credentials, cryptocurrency wallets, session tokens, and other sensitive information.
The observed chains used mshta.exe, obfuscated HTA and JavaScript, layered PowerShell stages, and multiple packed .NET components to retrieve and execute the final payload while evading analysis. Analysts reported AES and XOR decryption, SmartAssembly and .NET Reactor packing, AMSI bypass attempts, anti-sandbox and anti-debugging checks, Windows Defender evasion, and cleanup steps such as deleting downloaded archives after execution. One intrusion created files under C:\ProgramData, contacted iplogger.co, and launched an infostealer executable named jegule.exe, while another sample ultimately communicated through winhttp.dll and ws2_32.dll; investigators also recovered additional URLs from a Steam Community profile using ROT15 decoding.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Blackpoint Cyber documented a previously unknown Windows malware framework named Avalon that used a legal-document phishing lure, Proton Drive-hosted archive, ISO/LNK execution chain, and MSBuild-based stages before deploying a ransomware component called CrownX. The report detailed credential theft, lateral movement, ETW/AMSI interference, recovery sabotage, and file encryption with the .8hn2yc extension.
A separate analysis reported a Lumma Stealer campaign using a fake verification page at you-checked.com to copy a hidden PowerShell command, which fetched additional code and a ZIP payload from attacker-controlled domains. The write-up also described file creation under C:\ProgramData, contact with iplogger.co, execution of an infostealer named jegule.exe, and a second obfuscated mshta/HTA-based sample.
A forensic write-up detailed a multi-stage Lumma Stealer infection chain that began with a fake CAPTCHA page and led victims to execute a malicious PowerShell command via the Windows Run dialog. The analysis described subsequent HTA, PowerShell, .NET loader, AMSI bypass, and evasion stages culminating in Lumma Stealer execution.
A malware analysis detailed a Lumma Stealer infection chain in which a fake CAPTCHA page tricked users into running a clipboard-copied PowerShell command that fetched additional payloads and launched a masqueraded executable. The report also documented persistence behavior, suspicious network destinations, and multiple indicators of compromise including hashes, an IP address, and a DigitalOcean Spaces URL.
A 2024-09-09 analysis examined the second stage of a Lumma Stealer infection chain triggered by a fake CAPTCHA page, detailing an mshta-delivered loader that used layered JavaScript and PowerShell obfuscation plus AES-decrypted content to fetch additional payloads. The report linked the final injected payload in the legitimate BitLockerToGo process to Lumma Stealer and published IOCs including b-cdn URLs, .shop C2 domains, and SHA-256 hashes.
A late-August 2024 analysis documented a Lumma Stealer campaign using fake human-verification and CAPTCHA pages to trick users into executing a malicious PowerShell chain. The report described clipboard injection, mshta.exe abuse, payload delivery URLs, ZIP archives containing legitimate tools with malicious DLLs, and command-and-control domains used for exfiltration.
A public analysis described how Dolphin Loader abused the ITarian remote monitoring and management tool as part of its activity. The reference indicates the abuse pattern was documented and published by the researcher.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourceaviab1.github.io
Open sourcemedium.com
Open sourcev4ensics.gr
Open sourcemandarnaik016.in
Open sourcedenwp.com
Open sourcedenwp.com
Open sourcerussianpanda95.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.