FILEMembers
FILE

Same LummaStealer Build Reused Twice Across Two-Month Gap

A fake Snapchat-mod-APK site has served an identical, unsigned LummaStealer binary in both May and July, matched on imphash, vhash, and PE header. The same update adds a VBScript launcher and a timestomped downloader, pointing to a maturing multi-stage crimeware pipeline built around one unchanged payload.

Jun 29, 2026, 01:36 (UTC+9)Last seenJul 31, 2026Severity100ByCTX TeamIOC31MITRE57RegionsMGUS

An unsigned LummaStealer binary — identical import table, identical structural hash, identical PE compile timestamp — has surfaced twice in two months from the same fake Snapchat-mod-APK download site, first in May under the VirusTotal-derived label aco4cpki and again in July as millenium/milnmrat. The reuse is not a stylistic echo; it is the same build.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence