
Dormant Snapchat Lure Domain Wakes After 13 Months to Serve LummaStealer
A domain registered as a Snapchat mod APK resource sat inactive for thirteen months before its operator activated it in May 2026, serving six numbered Windows executables to Canadian users. The two-stage operation combines a commodity RAT dropper layer with LummaStealer payloads that harvest browser credentials and cryptocurrency wallet data, exfiltrating everything through the Telegram API.
A domain registered in April 2025 under the guise of a Snapchat mod APK resource sat completely inactive for thirteen months before its operator flipped a switch in May 2026: a Let's Encrypt TLS certificate was issued, six numbered Windows executables appeared at predictable paths, and a social-engineering notes file went live alongside them.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read