Cara Lin, Fortinet. (2024, January 8). Deceptive Cracked Software Spreads Lumma Variant on YouTube. Retrieved March 22, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareLumma Stealer | Lumma Stealer has used SmartAssembly to obfuscate .NET payloads. |
| T1041 Exfiltration Over C2 Channel |
MalwareLumma Stealer | Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels. |
| T1059.001 PowerShell |
MalwareLumma Stealer | Lumma Stealer has used PowerShell for initial user execution and other fuctions. |
| T1071.001 Web Protocols |
MalwareLumma Stealer | Lumma Stealer has used HTTP and HTTP for command and control communication. |
| T1082 System Information Discovery |
MalwareLumma Stealer | Lumma Stealer has gathered various system information from victim machines. |
| T1195 Supply Chain Compromise |
MalwareLumma Stealer | Lumma Stealer has been delivered through cracked software downloads. |
| T1497.001 System Checks |
MalwareLumma Stealer | Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection. |
| T1539 Steal Web Session Cookie |
MalwareLumma Stealer | Lumma Stealer has harvested cookies from various browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareLumma Stealer | Lumma Stealer has gathered credential and other information from multiple browsers. |
| T1564.003 Hidden Window |
MalwareLumma Stealer | Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window. |
| T1573.002 Asymmetric Cryptography |
MalwareLumma Stealer | Lumma Stealer has used HTTPS for command and control purposes. |
| T1620 Reflective Code Loading |
MalwareLumma Stealer | Lumma Stealer has used reflective loading techniques to load content into memory during execution. |
| T1622 Debugger Evasion |
MalwareLumma Stealer | Lumma Stealer has checked for debugger strings by invoking `GetForegroundWindow` and looks for strings containing “x32dbg”, “x64dbg”, “windbg”, “ollydbg”, “dnspy”, “immunity debugger”, “hyperdbg”, “debug”, “debugger”, “cheat engine”, “cheatengine” and “ida”. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.