Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts

## Cybersecurity: Lumma Infostealer Overview

Cybersecurity: Lumma Infostealer Overview

Since its emergence in August 2022, Lumma Infostealer has become a notable component of malware-as-a-service platforms, facilitating credential theft by various threat actors.

Lumma Infostealer is primarily delivered through phishing websites disguised as cracked software installers. It utilizes a Nullsoft Scriptable Install System (NSIS) package to avoid detection by signature-based security systems.

Upon execution, the malware reassembles fragmented AutoIt modules in memory and utilizes process hollowing to load obfuscated shellcode. This method replaces a legitimate process with the malware, disguising its activities as a benign executable.

Genians analysts identified Lumma Infostealer following a significant increase in credential theft reports in September 2025. Victims from both consumer and enterprise sectors reported unauthorized access to web sessions, remote desktop services, and digital asset wallets.

The malware steals browser cookies and account tokens, enabling seamless session hijacking and often bypassing multi-factor authentication. Cryptocurrency wallets stored in local databases, along with VPN and RDP credentials from configuration files, are exfiltrated to command-and-control (C2) domains via encrypted channels.

Lumma Infostealer is primarily delivered through phishing websites disguised as cracked software installers.
Daniel Brooks · Thehackingpost

The stolen data significantly increases the risks of identity fraud, financial loss, and extensive network breaches.

Lumma Infostealer employs a layered installer to bypass conventional security scanners. The NSIS installer drops a ZIP archive into the Temp directory, and a command-line script extracts a disguised Cabinet file. Components including fragments of an AutoIt script and its interpreter are merged into a single executable.

; Fragment of AutoIt loader Run("cmd.exe /c Contribute.docx") _ConsoleWrite("Launching AutoIt mode...") _ProcessCreate("Riding.pif", "", @SystemDir, 0, $pi) _WinAPI_WriteProcessMemory($pi.hProcess, $remoteAddr, $shellcode, BinaryLen($shellcode)) _WinAPI_SetThreadContext($pi.hThread, $context) _WinAPI_ResumeThread($pi.hThread)

The installer circumvents heuristic defenses by checking for security processes and adjusts execution accordingly. After injection, the malware decrypts C2 domains and establishes encrypted channels for data exfiltration.

Advertisement

To counter Lumma Infostealer, enhancing endpoint detection and response (EDR) systems with behavior-based analytics and threat intelligence integration is crucial. Monitoring process injection events, routinely auditing installer behaviors, and enforcing application allowlisting policies are recommended.

Implementing network-level blocks for known C2 domains and using sandbox detonation for suspicious NSIS packages can further mitigate the threat posed by this malware.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories