ATT&CKReferencesNetskope LummaStealer 2025

Netskope LummaStealer 2025

Leandro Fróes, Netskope. (2025, January 23). Lumma Stealer: Fake CAPTCHAs & New Techniques to Evade Detection. Retrieved March 22, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1036.008
Masquerade File Type
MalwareLumma Stealer

Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content.

T1059.001
PowerShell
MalwareLumma Stealer

Lumma Stealer has used PowerShell for initial user execution and other fuctions.

T1140
Deobfuscate/Decode Files or Information
MalwareLumma Stealer

Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell.

T1204
User Execution
MalwareLumma Stealer

Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell.

T1218.005
Mshta
MalwareLumma Stealer

Lumma Stealer has used mshta.exe to execute additional content.

T1547.001
Registry Run Keys / Startup Folder
MalwareLumma Stealer

Lumma Stealer has created registry keys to maintain persistence using `HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`.

T1620
Reflective Code Loading
MalwareLumma Stealer

Lumma Stealer has used reflective loading techniques to load content into memory during execution.

T1685
Disable or Modify Tools
MalwareLumma Stealer

Lumma Stealer has attempted to bypass Windows Antimalware Scan Interface (AMSI) by removing the string “AmsiScanBuffer” from the “clr.dll” module in memory to prevent it from being called.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.