ATT&CKReferencesQualys LummaStealer 2024

Qualys LummaStealer 2024

Vishwajeet Kumar, Qualys. (2024, October 20). Unmasking Lumma Stealer: Analyzing Deceptive Tactics with Fake CAPTCHA. Retrieved March 22, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareLumma Stealer

Lumma Stealer has used AES-encrypted payloads contained within PowerShell scripts.

T1041
Exfiltration Over C2 Channel
MalwareLumma Stealer

Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels.

T1055.012
Process Hollowing
MalwareLumma Stealer

Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload.

T1059.001
PowerShell
MalwareLumma Stealer

Lumma Stealer has used PowerShell for initial user execution and other fuctions.

T1059.010
AutoHotKey & AutoIT
MalwareLumma Stealer

Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables.

T1071.001
Web Protocols
MalwareLumma Stealer

Lumma Stealer has used HTTP and HTTP for command and control communication.

T1204
User Execution
MalwareLumma Stealer

Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell.

T1218.005
Mshta
MalwareLumma Stealer

Lumma Stealer has used mshta.exe to execute additional content.

T1518.001
Security Software Discovery
MalwareLumma Stealer

Lumma Stealer has detected antivirus processes using commands such as “tasklist” and “findstr.”

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.