
Lazarus Group Hides LummaC2 Stealer Behind Signed Installer and AWS CDN
A campaign tracked as CTXfy2q2my4yb deploys LummaC2 stealer payloads through trojanized game and utility installers signed with a valid DigiCert certificate, suppressing antivirus verdicts to 4 of 77 engines on the second-stage payload. AWS CloudFront subdomains scoring zero detections across 91 engines serve as C2 or staging relays, making network-layer blocking effectively impossible without disrupting legitimate cloud traffic.
Four indicators. Two signed Windows executables. Two AWS CloudFront subdomains that score zero detections across 91 engines. In practice, a delivery architecture that defeats network-layer blocking, suppresses antivirus verdicts on the second-stage payload to 4 out of 77 engines, and defeats dynamic analysis entirely — all simultaneously, all through infrastructure that any enterprise legitimately uses every day.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read