Greetings, readers of HackingBlogs! Recently, McAfee Labs discovered an alarming pattern of fake GitHub repositories spreading the Lumma Stealer virus. These repositories take use of GitHub’s credibility to attract foolish users by appearing as game hacks, cracked software, or free cryptocurrency utilities.
The objective? To trick users into downloading malicious software that poses as trustworthy content in order to steal private data, including browser history, login credentials, and even cryptocurrency wallet information. This post will explain how these attacks operate, why gamers and software seekers are vulnerable, and—above all—how to avoid being a victim of these fraud.
How May You Encounter Such Viruses : How the Attack Works Lumma Stealer
McAfee Labs has discovered malicious GitHub repositories that frequently contain game hacks, cracked software, or free cryptocurrency utilities that seem to have genuine advantages.
To trick people into believing them, these repositories are falsely presented with polished distribution licences, software screenshots, and thorough descriptions. Attackers primarily target customers who are trying to obtain free premium software like Adobe Express or Spotify, or who are looking for game cheats for games like Call of Duty, Roblox, or Minecraft.
After a user downloads a file from one of these repositories, it usually contains a version of the Lumma Stealer malware, which starts collecting private data, including browser history, login credentials, and cryptocurrency wallet information, and transmits it back to the attackers.
“Every week, a new set of repositories with a new malware variant is released, as the older repositories are detected and removed by GitHub. These repositories also include distribution licenses and software screenshots to enhance their appearance of legitimacy,”
What is LummaC2?
Since 2022, Lumma, a C-based malware that steals information, has been seen to be utilised as Malware-as-a-Service (MaaS). Lumma exfiltrates to a command and control server after stealing confidential information from the compromised system.
By inserting malicious code into the legitimate Windows process “dllhost.exe,” the malware’s second stage—a PE file—allows command and control communication, data exfiltration, and persistence through registry writing.
The malware’s involvement in data exfiltration or command execution is demonstrated by the way it uses HTTP POST requests to the endpoint /cfg to connect with a Command and Control (C2) server situated at IP address 188.68.22048. To avoid detection, the malware also uses a high degree of obfuscation and strategies including impersonating, such as utilising a unique User-Agent string to avoid being identified.
The Target Market: Risky Software Seekers and Gamers
Since they are more inclined to look for game mods, cheats, and cracked software, gamers and young people are a primary target of these evil efforts. A “Anti-Ban” mechanism to prevent account suspensions is frequently included in the promise of game hacks, like aimbots or speed hackers, making them appear even more tempting. They are, regrettably, easy targets for cybercriminals because of this.
These dishonest repositories put users at risk of downloading the Lumma Stealer virus by taking advantage of their desire for free access to premium software and an advantage in games. The software then secretly gathers and sends personal information, posing a serious risk to security and privacy.
Indicators of Compromise (IoCs) : Issued My McAfee
File Type | SHA256/URLs |
URLs | github[.]com/632763276327ermwhatthesigma/hack-apex-1egend |
github[.]com/VynnProjects/h4ck-f0rtnite | |
github[.]com/TechWezTheMan/Discord-AllinOne-Tool | |
github[.]com/UNDERBOSSDS/ESET-KeyGen-2024 | |
github[.]com/Rinkocuh/Dayz-Cheat-H4ck-A1mb0t | |
github[.]com/Magercat/Al-Photoshop-2024 | |
github[.]com/nate24321/minecraft-cheat2024 | |
github[.]com/classroom-x-games/counter-str1ke-2-h4ck | |
github[.]com/LittleHa1r/ESET-KeyGen-2024 | |
github[.]com/ferhatdermaster/Adobe-Express-2024 | |
github[.]com/CrazFrogb/23fasd21/releases/download/loader/Loader[.]Github[.]zip | |
github[.]com/flashkiller2018/Black-Ops-6-Cheats-including-Unlocker-Tool-and-RICOCHET-Bypass | |
github[.]com/Notalight/h4ck-f0rtnite | |
github[.]com/Ayush9876643/r0blox-synapse-x-free | |
github[.]com/FlqmzeCraft/cheat-escape-from-tarkov | |
github[.]com/Ayush9876643/cheat-escape-from-tarkov | |
github[.]com/Ayush9876643/rust-hack-fr33 | |
github[.]com/ppetriix/rust-hack-fr33 | |
github[.]com/Ayush9876643/Roblox-Blox-Fruits-Script-2024 | |
github[.]com/LandonPasana21/Roblox-Blox-Fruits-Script-2024 | |
github[.]com/Ayush9876643/Rainbow-S1x-Siege-Cheat | |
github[.]com/Ayush9876643/SonyVegas-2024 | |
github[.]com/123456789433/SonyVegas-2024 | |
github[.]com/Ayush9876643/Nexus-Roblox | |
github[.]com/cIeopatra/Nexus-Roblox | |
github[.]com/Ayush9876643/m0dmenu-gta5-free | |
github[.]com/GerardoR17/m0dmenu-gta5-free | |
github[.]com/Ayush9876643/minecraft-cheat2024 | |
github[.]com/RakoBman/cheat-apex-legends-download | |
github[.]com/Ayush9876643/cheat-apex-legends-download | |
github[.]com/cIiqued/FL-Studio | |
github[.]com/Ayush9876643/FL-Studio | |
github[.]com/Axsle-gif/h4ck-f0rtnite | |
github[.]com/Ayush9876643/h4ck-f0rtnite | |
github[.]com/SUPAAAMAN/m0dmenu-gta5-free | |
github[.]com/atomicthefemboy/cheat-apex-legends-download | |
github[.]com/FlqmzeCraft/cheat-escape-from-tarkov | |
github[.]com/Notalight/h4ck-f0rtnite | |
github[.]com/Notalight/FL-Studio | |
github[.]com/Notalight/r0blox-synapse-x-free | |
github[.]com/Notalight/cheat-apex-legends-download | |
github[.]com/Notalight/cheat-escape-from-tarkov | |
github[.]com/Notalight/rust-hack-fr33 | |
github[.]com/Notalight/Roblox-Blox-Fruits-Script-2024 | |
github[.]com/Notalight/Rainbow-S1x-Siege-Cheat | |
github[.]com/Notalight/SonyVegas-2024 | |
github[.]com/Notalight/Nexus-Roblox | |
github[.]com/Notalight/minecraft-cheat2024 | |
github[.]com/Notalight/m0dmenu-gta5-free | |
github[.]com/ZinkosBR/r0blox-synapse-x-free | |
github[.]com/ZinkosBR/cheat-escape-from-tarkov | |
github[.]com/ZinkosBR/rust-hack-fr33 | |
github[.]com/ZinkosBR/Roblox-Blox-Fruits-Script-2024 | |
github[.]com/ZinkosBR/Rainbow-S1x-Siege-Cheat | |
github[.]com/ZinkosBR/Nexus-Roblox | |
github[.]com/ZinkosBR/m0dmenu-gta5-free | |
github[.]com/ZinkosBR/minecraft-cheat2024 | |
github[.]com/ZinkosBR/h4ck-f0rtnite | |
github[.]com/ZinkosBR/FL-Studio | |
github[.]com/ZinkosBR/cheat-apex-legends-download | |
github[.]com/EliminatorGithub/counter-str1ke-2-h4ck | |
Github[.]com/ashishkumarku10/call-0f-duty-warz0ne-h4ck | |
EXEs | CB6DDBF14DBEC8AF55986778811571E6 |
C610FD2A7B958E79F91C5F058C7E3147 | |
3BBD94250371A5B8F88B969767418D70 | |
CF19765D8A9A2C2FD11A7A8C4BA3DEDA | |
69E530BC331988E4E6FE904D2D23242A | |
35A2BDC924235B5FA131095985F796EF | |
EB604E2A70243ACB885FE5A944A647C3 | |
690DBCEA5902A1613CEE46995BE65909 | |
2DF535AFF67A94E1CDAD169FFCC4562A | |
84100E7D46DF60FE33A85F16298EE41C | |
00BA06448D5E03DFBFA60A4BC2219193 | |
C2 Domains | 104.21.48.1 |
104.21.112.1 | |
104.21.16.1 |