Buddy Tancio, Fe Cureg, and Jovit Samaniego, Trend Micro. (2025, January 30). Lumma Stealer’s GitHub-Based Delivery Explored via Managed Detection and Response. Retrieved March 22, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1074.001 Local Data Staging |
MalwareLumma Stealer | Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data. |
| T1082 System Information Discovery |
MalwareLumma Stealer | Lumma Stealer has gathered various system information from victim machines. |
| T1195 Supply Chain Compromise |
MalwareLumma Stealer | Lumma Stealer has been delivered through cracked software downloads. |
| T1218.015 Electron Applications |
MalwareLumma Stealer | Lumma Stealer as leveraged Electron Applications to disable GPU sandboxing to avoid detection by security software. |
| T1497.001 System Checks |
MalwareLumma Stealer | Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection. |
| T1539 Steal Web Session Cookie |
MalwareLumma Stealer | Lumma Stealer has harvested cookies from various browsers. |
| T1553.002 Code Signing |
MalwareLumma Stealer | Lumma Stealer has used valid code signing digital certificates from ConsolHQ LTD and Verandah Green Limited to appear legitimate. |
| T1555.003 Credentials from Web Browsers |
MalwareLumma Stealer | Lumma Stealer has gathered credential and other information from multiple browsers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.