Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Lunar Spider Infected Windows Machine in Single Click and Harvested Login Credentials

A cybercriminal group identified as Lunar Spider successfully compromised a Windows system through a single malicious click, enabling them to harvest credentials and maintain access for nearly two months.

A cybercriminal group identified as Lunar Spider successfully compromised a Windows system through a single malicious click, enabling them to harvest credentials and maintain access for nearly two months.

The intrusion began in May 2024, illustrating how initial access can escalate to full domain compromise. The attack started when a user executed a heavily obfuscated JavaScript file disguised as a tax form, named "FormW-9Ver-i4053b043910-86g91352u7972-6495q3.js".

This file was reported by security researchers and associated with the Lunar Spider group. It contained minimal executable code dispersed among filler content to evade detection systems.

The JavaScript payload triggered the download of an MSI package from a remote server, deploying a Brute Ratel DLL file using the Windows utility rundll32.

This approach allowed the threat actors to inject Latrodectus malware into the explorer.exe process while establishing command and control communications with multiple CloudFlare proxied domains.

Within the first hour, the Latrodectus payload retrieved a specialized stealer module to harvest credentials from compromised systems.

The malware targeted 29 Chromium-based browsers, including Google Chrome, Microsoft Edge, Yandex Browser, Vivaldi, and others. Firefox was targeted through profile enumeration aiming at cookies.sqlite database files.

The intrusion began in May 2024, illustrating how initial access can escalate to full domain compromise.
Adam Foster · Thehackingpost

The credential harvesting extended to email configurations from Microsoft Outlook (versions 11.0-17.0) by querying Windows registry keys. The stealer extracted server configurations, including SMTP, POP3, IMAP, and NNTP server addresses, port numbers, usernames, and encrypted passwords, granting attackers comprehensive access to the victim's communication infrastructure.

On day three, the attackers discovered an unattend.xml Windows Answer file containing plaintext domain administrator credentials from an automated deployment process.

On day four, a binary named lsassa.exe was deployed and executed via BackConnect on the compromised host.

This discovery provided high-privilege access to the domain environment, expanding their potential impact and lateral movement capabilities.

Lunar Spider employed sophisticated evasion techniques, including process injection into legitimate Windows processes such as explorer.exe, sihost.exe, and spoolsv.exe.

Advertisement

They established multiple persistence mechanisms, including Registry Run keys and scheduled tasks, ensuring access would survive system restarts and basic remediation attempts.

The attackers deployed multiple command and control frameworks, including Brute Ratel, Latrodectus, and Cobalt Strike beacons, creating redundant communication channels with their infrastructure.

The threat actors maintained intermittent command and control access for nearly two months. On day twenty, they exfiltrated data from file share servers using a renamed Rclone binary over FTP connections, with the process taking approximately ten hours.

No ransomware deployment was observed, suggesting the attackers prioritized data theft over destructive activities.

This campaign highlights the persistent threat posed by well-resourced cybercriminal groups and underscores the importance of robust security monitoring and rapid incident response capabilities.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories