FILEMembers
FILE

Fake Adobe Plugin Delivers Lumma Stealer and Cryptominer via Four-Layer Chain

A typosquat domain impersonating Adobe software distributes an encrypted payload chain attributed with medium confidence to BlueBottle. The campaign deploys Lumma stealer and CoinMiner03 simultaneously on compromised hosts, while an automated build pipeline stamps out near-identical dropper containers with shared version-info metadata and matching timestamps.

May 30, 2026, 21:15 (UTC+9)Last seenMay 30, 2026Severity77ByCTX TeamActorBlueBottleOpera1erIOC15RegionsUS

A single typosquat domain — adobe-plugin.info — sits at the front of a payload chain that is considerably more engineered than its lure suggests. Behind the Adobe branding lies a structured, automated build pipeline producing at least four distinct malware components: a GCleaner MSIL trojan, a PEiD-packed dropper variant, a compact Nitol persistence stub, and a dual-purpose monetisation stage that runs Lumma stealer and a cryptominer simultaneously on the same compromised host.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence