
Gaming-Cheat Lure Hides Kernel-Level LummaStealer Campaign
A trojanized HWID-spoofer toolkit distributed across three operator-controlled domains is delivering LummaStealer alongside a two-driver kernel evasion stack built around an expired EV-signed vulnerable driver. Active browser-credential harvesting across multiple victim machines was confirmed as recently as 2026-06-06, one day before initial detection.
A trojanized HWID-spoofer toolkit — distributed under gaming-cheat branding from at least three operator-controlled download endpoints — is delivering LummaStealer alongside a purpose-built kernel evasion stack that combines an expired EV-signed vulnerable driver with a test-certificate-signed spoofer component. The campaign's most recently observed artifact, a browser-store harvest file first seen on 2026-06-06, confirms active credential collection was underway within hours of CTX Team's…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read