Thursday, May 15, 2025
Homecyber securityCybercriminals Exploit GitHub Infrastructure to Distribute Lumma Stealer

Cybercriminals Exploit GitHub Infrastructure to Distribute Lumma Stealer

Published on

SIEM as a Service

Follow Us on Google News

In a recent investigation, Trend Micro’s Managed XDR team identified a sophisticated malware campaign exploiting GitHub’s release infrastructure to distribute Lumma Stealer, along with SectopRAT, Vidar, and Cobeacon malware.

This campaign underscores the evolving tactics of attackers leveraging trusted platforms to deliver malicious payloads.

Abuse of Trusted Platforms

The attack begins with users downloading files via temporary secure URLs hosted on GitHub’s release mechanism.

- Advertisement - Google News

Files such as Pictore.exe and App_aeIGCY3g.exe both confirmed to be Lumma Stealer variants exfiltrate sensitive data, including credentials, cryptocurrency wallets, and system details, while establishing connections to command-and-control (C&C) servers.

GitHub Infrastructure
Downloading the Lumma Stealer binary Pictore.exe from its Github repository

The malicious binaries, signed with revoked certificates, exploit GitHub repositories for distribution while leveraging PowerShell scripts and shell commands to establish persistence and evade detection.

Further analysis revealed that the campaign overlaps with tactics used by the Stargazer Goblin group, a known threat actor employing compromised websites and GitHub for payload distribution.

Consistent URL patterns and the redirection of victims to GitHub-hosted malware highlight deliberate planning.

Modular Malware Deployment

The infection chain is complex and employs modular deployment. The initial Lumma Stealer files dynamically dropped and executed additional malware, including:

  • SectopRAT: Facilitates remote access and further exfiltration through processes such as browser data theft and persistence mechanisms (e.g., startup entries and scheduled tasks).
  • Vidar: Copies browser data and cloud storage files, establishing connections to external C&C servers for data exfiltration.
  • Lumma Stealer Variant: Employs obfuscated PowerShell scripts to contact malicious domains, download payloads, and extract sensitive user details.

The attackers demonstrated advanced evasion techniques by using Electron-based frameworks for malware execution and custom settings to bypass sandboxing.

GitHub Infrastructure
The chain of events in an attack involving Vidar

Connections to IP addresses such as 192[.]142[.]10[.]246 and domains like lumdukekiy[.]shop facilitated external communication.

Additionally, reconnaissance commands and code execution flags were used to gather system and environment information stealthily.

The campaign marks a notable evolution in malware distribution tactics, with attackers leveraging GitHub to bypass security defenses and normalize malicious payloads.

The deployment of multiple malware families, including Lumma Stealer, illustrates a strategic shift toward modular, multi-purpose attacks.

Trend Micro’s Managed XDR platform proved instrumental in uncovering this campaign, emphasizing the importance of robust cyber threat intelligence and proactive monitoring in mitigating modern cyber threats.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN Sandox -> Try for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Critical BitLocker Flaw Exploited in Minutes: Bitpixie Vulnerability Proof of Concept Unveiled

Security researchers have demonstrated a non-invasive method to bypass Microsoft BitLocker encryption on Windows...

Google Chrome Zero-Day Vulnerability (CVE-2025-4664) Actively Exploited in The Wild

Google has rolled out a fresh Stable Channel update for the Chrome browser across...

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...

TA406 Hackers Target Government Entities to Steal Login Credentials

The North Korean state-sponsored threat actor TA406, also tracked as Opal Sleet and Konni,...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Critical BitLocker Flaw Exploited in Minutes: Bitpixie Vulnerability Proof of Concept Unveiled

Security researchers have demonstrated a non-invasive method to bypass Microsoft BitLocker encryption on Windows...

Google Chrome Zero-Day Vulnerability (CVE-2025-4664) Actively Exploited in The Wild

Google has rolled out a fresh Stable Channel update for the Chrome browser across...

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...