Vishwajeet Kumar, Qualys. (2024, October 20). Unmasking Lumma Stealer: Analyzing Deceptive Tactics with Fake CAPTCHA. Retrieved March 22, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareLumma Stealer | Lumma Stealer has used AES-encrypted payloads contained within PowerShell scripts. |
| T1041 Exfiltration Over C2 Channel |
MalwareLumma Stealer | Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels. |
| T1055.012 Process Hollowing |
MalwareLumma Stealer | Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload. |
| T1059.001 PowerShell |
MalwareLumma Stealer | Lumma Stealer has used PowerShell for initial user execution and other fuctions. |
| T1059.010 AutoHotKey & AutoIT |
MalwareLumma Stealer | Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables. |
| T1071.001 Web Protocols |
MalwareLumma Stealer | Lumma Stealer has used HTTP and HTTP for command and control communication. |
| T1204 User Execution |
MalwareLumma Stealer | Lumma Stealer has been distributed through a fake CAPTCHA that presents instructions to the victim to open Windows Run window (“Windows Button + R”) and paste clipboard contents (“CTRL + V”) and press “Enter” to execute a Base64-encoded PowerShell. |
| T1218.005 Mshta |
MalwareLumma Stealer | Lumma Stealer has used mshta.exe to execute additional content. |
| T1518.001 Security Software Discovery |
MalwareLumma Stealer | Lumma Stealer has detected antivirus processes using commands such as “tasklist” and “findstr.” |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.