
Lumma Stealer Hides Behind Iranian ISP and Seychelles Shell in Domainless C2
A Lumma Stealer campaign luring cryptocurrency users with a fake 'BTC CRACKER.exe' utility routes stolen data to four raw IP addresses split across an Iranian ISP and a freshly provisioned Seychelles-registered bulletproof provider, with no DNS layer whatsoever. The operator pre-staged the bulletproof infrastructure six to eight weeks before the payload appeared in the wild, and a single hardcoded panel path — /diamo/data.php — binds the entire architecture together.
Four raw IP addresses. No domains. One hardcoded path. That is the entirety of the network-layer architecture behind a Lumma Stealer campaign that has been circulating since October 2025 under the filename "BTC CRACKER.exe" — a lure aimed squarely at cryptocurrency users who believe they are downloading a wallet-cracking utility.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read