C&CMembers
C&C

Gaming-Cheat Lure Hides Kernel-Level LummaStealer Campaign

A trojanized HWID-spoofer toolkit distributed across three operator-controlled domains is delivering LummaStealer alongside a two-driver kernel evasion stack built around an expired EV-signed vulnerable driver. Active browser-credential harvesting across multiple victim machines was confirmed as recently as 2026-06-06, one day before initial detection.

Jun 7, 2026, 19:39 (UTC+9)Last seenJun 7, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC31MITRE24

A trojanized HWID-spoofer toolkit — distributed under gaming-cheat branding from at least three operator-controlled download endpoints — is delivering LummaStealer alongside a purpose-built kernel evasion stack that combines an expired EV-signed vulnerable driver with a test-certificate-signed spoofer component. The campaign's most recently observed artifact, a browser-store harvest file first seen on 2026-06-06, confirms active credential collection was underway within hours of CTX Team's…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence