FILEMembers
FILE

Dormant Snapchat Lure Domain Wakes After 13 Months to Serve LummaStealer

A domain registered as a Snapchat mod APK resource sat inactive for thirteen months before its operator activated it in May 2026, serving six numbered Windows executables to Canadian users. The two-stage operation combines a commodity RAT dropper layer with LummaStealer payloads that harvest browser credentials and cryptocurrency wallet data, exfiltrating everything through the Telegram API.

Jun 17, 2026, 11:08 (UTC+9)Last seenJun 17, 2026Severity100ByCTX TeamIOC18MITRE41RegionsCA

A domain registered in April 2025 under the guise of a Snapchat mod APK resource sat completely inactive for thirteen months before its operator flipped a switch in May 2026: a Let's Encrypt TLS certificate was issued, six numbered Windows executables appeared at predictable paths, and a social-engineering notes file went live alongside them.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence