Cybereaon Security Services Team. (n.d.). Your Data Is Under New Lummanagement: The Rise of LummaStealer. Retrieved March 22, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareLumma Stealer | Lumma Stealer has used PowerShell for initial user execution and other fuctions. |
| T1059.006 Python |
MalwareLumma Stealer | Lumma Stealer has used malicious Python scripts to execute payloads. |
| T1059.010 AutoHotKey & AutoIT |
MalwareLumma Stealer | Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables. |
| T1082 System Information Discovery |
MalwareLumma Stealer | Lumma Stealer has gathered various system information from victim machines. |
| T1113 Screen Capture |
MalwareLumma Stealer | Lumma Stealer has taken screenshots of victim machines. |
| T1119 Automated Collection |
MalwareLumma Stealer | Lumma Stealer has automated collection of various information including cryptocurrency wallet details. |
| T1176.001 Browser Extensions |
MalwareLumma Stealer | Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data. |
| T1195 Supply Chain Compromise |
MalwareLumma Stealer | Lumma Stealer has been delivered through cracked software downloads. |
| T1204 User Execution |
MalwareLumma Stealer | Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell. |
| T1204.002 Malicious File |
MalwareLumma Stealer | Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files. |
| T1217 Browser Information Discovery |
MalwareLumma Stealer | Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers. |
| T1539 Steal Web Session Cookie |
MalwareLumma Stealer | Lumma Stealer has harvested cookies from various browsers. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLumma Stealer | Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`. |
| T1555.003 Credentials from Web Browsers |
MalwareLumma Stealer | Lumma Stealer has gathered credential and other information from multiple browsers. |
| T1566.001 Spearphishing Attachment |
MalwareLumma Stealer | Lumma Stealer has been delivered through phishing emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareLumma Stealer | Lumma Stealer has been delivered through phishing emails containing malicious links. |
| T1574.001 DLL |
MalwareLumma Stealer | Lumma Stealer has leveraged legitimate applications to then side-load malicious DLLs during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.