Security researchers reported a sharp rise in the Rugmi malware loader, tracked by ESET as Win/TrojanDownloader.Rugmi, after detections jumped from single digits to hundreds per day. Rugmi has been used to deliver multiple information stealers, including Lumma Stealer, Vidar, RecordBreaker, and Rescoms. Analysts said the malware appears in several forms: a downloader that fetches an encrypted payload, a loader that executes a payload embedded in its own resources, and a variant that launches a payload from an external disk file.
The activity reflects a broader criminal ecosystem built around commodity malware delivery and remote access abuse. Researchers noted that Lumma Stealer is sold through a malware-as-a-service model and is distributed through malvertising, fake browser updates, cracked software installers, and abuse of Discord CDN infrastructure. Separately, McAfee detailed how attackers have repurposed the legitimate NetSupport remote administration tool as a RAT, with initial access brokers using it against targets in the U.S. and Canada to establish footholds for follow-on compromise.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
ESET telemetry showed Rugmi detections continued at sharply elevated levels in November 2023, with hundreds of daily detections. The loader's activity reflected broader use of ready-made malware services to distribute commodity stealers.
ESET telemetry showed detections of the Rugmi malware loader surged in October 2023, rising from single-digit daily detections toward hundreds per day. Rugmi was observed delivering multiple stealers including Lumma, Vidar, RecordBreaker, and Rescoms.
Trend Micro revealed that Discord's content delivery network was being used to host and propagate Lumma Stealer. The campaign used random and compromised Discord accounts to send direct messages offering money or Discord Nitro and directing targets to a malicious executable masquerading as iMagic Inventory.
ESET published details on the Rugmi malware loader in its Threat Report H2 2023, describing three component types: a downloader that retrieves an encrypted payload, a loader that executes a payload from internal resources, and a loader that runs a payload from an external disk file.
McAfee Labs disclosed a new variant of NetSupport RAT being used by initial access brokers against targets in the U.S. and Canada. The company said the infection chain starts with obfuscated JavaScript that launches PowerShell to retrieve remote-control and stealer malware from an actor-controlled server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.