APTMembers
APT

Fake YCleanner App Delivers LummaStealer After Four-Month Build Campaign

A Windows executable branded as a system-cleaning utility spent four months in development before deploying LummaStealer credential theft and XMRig cryptomining against Romanian targets. The campaign's encrypted outer container achieved zero detections across 77 antivirus engines, concealing a binder set of eight payloads built in a single automated two-minute window.

Jun 24, 2026, 01:23 (UTC+9)Last seenJun 24, 2026Severity77ByCTX TeamActorBlueBottleOpera1erIOC18RegionsRO

A Windows executable branded as a system-cleaning utility — product name "YCleanner," internal name YC.exe, version 1.3.2.5 — has been circulating as the delivery vehicle for a dual-purpose attack chain combining LummaStealer credential theft with XMRig cryptomining, targeting Romania. The campaign's most operationally distinctive feature is not the payload itself but the architecture surrounding it: an encrypted outer container that achieves a clean sweep of 0/77 antivirus detections at the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence