Malware.View on attack.mitre.org
Lumma Stealer is an information stealer malware family in use since at least 2022. Lumma Stealer is a Malware as a Service (MaaS) where captured data has been sold in criminal markets to Initial Access Brokers.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Lumma Stealer has used SmartAssembly to obfuscate .NET payloads. |
| T1027.013 Encrypted/Encoded File |
Lumma Stealer has used AES-encrypted payloads contained within PowerShell scripts. |
| T1036.008 Masquerade File Type |
Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content. |
| T1041 Exfiltration Over C2 Channel |
Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels. |
| T1055.012 Process Hollowing |
Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload. |
| T1059.001 PowerShell |
Lumma Stealer has used PowerShell for initial user execution and other fuctions. |
| T1059.006 Python |
Lumma Stealer has used malicious Python scripts to execute payloads. |
| T1059.010 AutoHotKey & AutoIT |
Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables. |
| T1071.001 Web Protocols |
Lumma Stealer has used HTTP and HTTP for command and control communication. |
| T1074.001 Local Data Staging |
Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data. |
| T1082 System Information Discovery |
Lumma Stealer has gathered various system information from victim machines. |
| T1113 Screen Capture |
Lumma Stealer has taken screenshots of victim machines. |
| T1119 Automated Collection |
Lumma Stealer has automated collection of various information including cryptocurrency wallet details. |
| T1140 Deobfuscate/Decode Files or Information |
Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell. |
| T1176.001 Browser Extensions |
Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.