ATT&CKReferencesFortinet LummaStealer 2024

Fortinet LummaStealer 2024

Cara Lin, Fortinet. (2024, January 8). Deceptive Cracked Software Spreads Lumma Variant on YouTube. Retrieved March 22, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareLumma Stealer

Lumma Stealer has used SmartAssembly to obfuscate .NET payloads.

T1041
Exfiltration Over C2 Channel
MalwareLumma Stealer

Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels.

T1059.001
PowerShell
MalwareLumma Stealer

Lumma Stealer has used PowerShell for initial user execution and other fuctions.

T1071.001
Web Protocols
MalwareLumma Stealer

Lumma Stealer has used HTTP and HTTP for command and control communication.

T1082
System Information Discovery
MalwareLumma Stealer

Lumma Stealer has gathered various system information from victim machines.

T1195
Supply Chain Compromise
MalwareLumma Stealer

Lumma Stealer has been delivered through cracked software downloads.

T1497.001
System Checks
MalwareLumma Stealer

Lumma Stealer has queried system resources on the victim device to identify if it is executing in a sandbox or virtualized environments, checking usernames, conducting WMI queries for system details, checking for files commonly found in virtualized environments, searching system services, and inspecting process names. Lumma Stealer has checked system GPU configurations for sandbox detection.

T1539
Steal Web Session Cookie
MalwareLumma Stealer

Lumma Stealer has harvested cookies from various browsers.

T1555.003
Credentials from Web Browsers
MalwareLumma Stealer

Lumma Stealer has gathered credential and other information from multiple browsers.

T1564.003
Hidden Window
MalwareLumma Stealer

Lumma Stealer has utilized the .NET `ProcessStartInfo` class features to prevent the process from creating a visible window through setting the `CreateNoWindow` setting to “True,” which allows the executed command or script to run without displaying a command prompt window.

T1573.002
Asymmetric Cryptography
MalwareLumma Stealer

Lumma Stealer has used HTTPS for command and control purposes.

T1620
Reflective Code Loading
MalwareLumma Stealer

Lumma Stealer has used reflective loading techniques to load content into memory during execution.

T1622
Debugger Evasion
MalwareLumma Stealer

Lumma Stealer has checked for debugger strings by invoking `GetForegroundWindow` and looks for strings containing “x32dbg”, “x64dbg”, “windbg”, “ollydbg”, “dnspy”, “immunity debugger”, “hyperdbg”, “debug”, “debugger”, “cheat engine”, “cheatengine” and “ida”.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.