Lummac2

Malware updated a month ago (2024-11-29T13:55:34.006Z)
Download STIX
Preview STIX
LummaC2 is a malicious software (malware) that was initially identified in Russian-speaking forums in 2022. The malware, written in C and distributed as Malware-as-a-Service (MaaS), has been actively developed over time, with researchers noting that LummaC2 4.0 operates as a dynamic malware strain. It's designed to steal information from infected systems and is known for its obfuscated PowerShell tactics. Techniques such as shellcode encryption, code obfuscation, and embedding LummaC2 and Rhadamanthys information stealers into legitimate binaries are used to evade antivirus detection and sandbox analysis. In 2023, the use of LummaC2 expanded alongside several other malware families including Nokoyawa and BlackBasta ransomware, Minodo, Diceloader, Aresloader, and Canyon. These malwares were obtained or purchased from FIN7 developers. LummaC2 has also appeared in new malware strains used for initial access or information stealing, such as SVCReady, CargoBay, Matanbuchus, Pikabot, Aresloader, Vidar, and Minodo. This shows a significant broadening of its application across different cyber threat landscapes. The initial attack vector of LummaC2 involves obfuscated PowerShell commands that download and execute payloads, often leveraging Microsoft’s legitimate Living-off-the-Land binaries (LOLbins) like Mshta.exe and Dllhost.exe for malicious purposes. LummaC2's techniques align with various MITRE ATT&CK frameworks, such as Process Injection (T1055) and Persistence via Registry Modification (T1547.001). The continuous development and adaptation of LummaC2 highlight the evolving nature of cyber threats and underscore the need for robust, up-to-date cybersecurity measures.
Description last updated: 2024-11-21T16:05:49.729Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Lummac2 Stealer is a possible alias for Lummac2. LummaC2 Stealer is a type of malware that has gained significant attention due to its capacity to steal sensitive information, including digital wallets and user credentials. It can even target two-factor authentication (2FA) browser extensions, making it particularly threatening. Over the past year
3
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Infostealer
Payload
Credentials
Ransomware
Sandbox
Infostealers
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Redline Malware is associated with Lummac2. RedLine is a type of malware, or malicious software, designed to exploit and damage computer systems. It infects systems through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, it can steal personal information, disrupt operations, or even hold data hostage forUnspecified
3
The Vidar Malware is associated with Lummac2. Vidar is a malicious software (malware) that primarily targets Windows systems, written in C++ and based on the Arkei stealer. It has historically been favored by threat actors who sell logs through marketplaces like 2easy, alongside other infostealers such as Raccoon, RedLine, and AZORult. The malwUnspecified
3
The Raccoon Malware is associated with Lummac2. Raccoon is a malicious software (malware) developed by Russian-speaking coders, first spotted in April 2019. It was designed to steal sensitive data such as credit card information, email credentials, cryptocurrency wallets, and more from its victims. The malware is offered as a service (MaaS) for $Unspecified
2
Source Document References
Information about the Lummac2 Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
InfoSecurity-magazine
a month ago
Malwarebytes
a month ago
DARKReading
2 months ago
InfoSecurity-magazine
4 months ago
InfoSecurity-magazine
4 months ago
InfoSecurity-magazine
9 months ago
CERT-EU
9 months ago
CERT-EU
10 months ago
CERT-EU
10 months ago
BankInfoSecurity
10 months ago
CERT-EU
10 months ago
CERT-EU
10 months ago
CERT-EU
a year ago
CERT-EU
a year ago
DARKReading
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
InfoSecurity-magazine
a year ago