C&CMembers
C&C

Lumma Stealer Hides Behind Iranian ISP and Seychelles Shell in Domainless C2

A Lumma Stealer campaign luring cryptocurrency users with a fake 'BTC CRACKER.exe' utility routes stolen data to four raw IP addresses split across an Iranian ISP and a freshly provisioned Seychelles-registered bulletproof provider, with no DNS layer whatsoever. The operator pre-staged the bulletproof infrastructure six to eight weeks before the payload appeared in the wild, and a single hardcoded panel path — /diamo/data.php — binds the entire architecture together.

Jun 29, 2026, 05:23 (UTC+9)Last seenJun 29, 2026Severity100ByCTX TeamIOC13MITRE33RegionsUS

Four raw IP addresses. No domains. One hardcoded path. That is the entirety of the network-layer architecture behind a Lumma Stealer campaign that has been circulating since October 2025 under the filename "BTC CRACKER.exe" — a lure aimed squarely at cryptocurrency users who believe they are downloading a wallet-cracking utility.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence