ATT&CKReferencesCybereason LumaStealer Undated

Cybereason LumaStealer Undated

Cybereaon Security Services Team. (n.d.). Your Data Is Under New Lummanagement: The Rise of LummaStealer. Retrieved March 22, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareLumma Stealer

Lumma Stealer has used PowerShell for initial user execution and other fuctions.

T1059.006
Python
MalwareLumma Stealer

Lumma Stealer has used malicious Python scripts to execute payloads.

T1059.010
AutoHotKey & AutoIT
MalwareLumma Stealer

Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables.

T1082
System Information Discovery
MalwareLumma Stealer

Lumma Stealer has gathered various system information from victim machines.

T1113
Screen Capture
MalwareLumma Stealer

Lumma Stealer has taken screenshots of victim machines.

T1119
Automated Collection
MalwareLumma Stealer

Lumma Stealer has automated collection of various information including cryptocurrency wallet details.

T1176.001
Browser Extensions
MalwareLumma Stealer

Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data.

T1195
Supply Chain Compromise
MalwareLumma Stealer

Lumma Stealer has been delivered through cracked software downloads.

T1204
User Execution
MalwareLumma Stealer

Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell.

T1204.002
Malicious File
MalwareLumma Stealer

Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files.

T1217
Browser Information Discovery
MalwareLumma Stealer

Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers.

T1539
Steal Web Session Cookie
MalwareLumma Stealer

Lumma Stealer has harvested cookies from various browsers.

T1547.001
Registry Run Keys / Startup Folder
MalwareLumma Stealer

Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`.

T1555.003
Credentials from Web Browsers
MalwareLumma Stealer

Lumma Stealer has gathered credential and other information from multiple browsers.

T1566.001
Spearphishing Attachment
MalwareLumma Stealer

Lumma Stealer has been delivered through phishing emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareLumma Stealer

Lumma Stealer has been delivered through phishing emails containing malicious links.

T1574.001
DLL
MalwareLumma Stealer

Lumma Stealer has leveraged legitimate applications to then side-load malicious DLLs during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.