
Same LummaStealer Build Reused Twice Across Two-Month Gap
A fake Snapchat-mod-APK site has served an identical, unsigned LummaStealer binary in both May and July, matched on imphash, vhash, and PE header. The same update adds a VBScript launcher and a timestomped downloader, pointing to a maturing multi-stage crimeware pipeline built around one unchanged payload.
An unsigned LummaStealer binary — identical import table, identical structural hash, identical PE compile timestamp — has surfaced twice in two months from the same fake Snapchat-mod-APK download site, first in May under the VirusTotal-derived label aco4cpki and again in July as millenium/milnmrat. The reuse is not a stylistic echo; it is the same build.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read