Automatically translated.View original post

The old LummaStealer is back.

The old LummaStealer is back. This time, Trendy used ClickFix to embed malware into the bait machine.

The most famous type of malware stealing data from the victim's machine or Infostealer is probably inevitable. LummaStealer and the most popular current malware release method mentioned must be ClickFix. Using a fraudulent malware notification screen to do the malware installation command, many parties may think about what it would be like if these two came together and now it happens.

According to a report by the website Cyber Security News, a new LummaStealer malware distribution campaign was detected through a popular method like ClickFix through the use of fake CaptCha. A research team from Bitdefender, a company that develops anti-malware tools, revealed that hackers will use fake websites that claim to be Crack sites, video games, and software to be available for free. Or they may claim to be pirated movie downloading sites. When the victim enters the site and encounters fake CaptCha and follows the instructions made on the screen, CaptCha will lead to downloading malware. It's named CastleLoader in the end.

By malware, CastleLoader serves as a base for downloading and installing LummaStealer malware. It works through AutoIT to hide malware code and check the Obfuscation system with random word variables and Dead Code. In the next step, before loading the LummaStealer's payload, the malware will check the system environment first to make sure it runs on the victim's machine, not in a simulated environment like the Sandbox system, VMware, or VirtualBox, by checking the computer name or user name. If found running in the environment, the malware will stop immediately. In addition, the malware has created fake domain names that do not exist to deceive the DNS Lookup monitoring system.

And if everything is safe, this malware will create persistence on the system by copying itself into the Local Application Data folder (% LOCALAPPDATA%) and creating a shortcut inside the Startup folder to guarantee that the malware will be activated every time it is rebooted.

For LummaStealer malware, the malware focuses on Windows operating system users. The malware is effective at stealing various forms of data, such as web browser passwords, Session Cookies files, Kryptokerrency wallet information, or even Token for double-layer authentication (2FA or 2 Factors Authentication).

# Trending # Lemon 8 Howtoo # lemon 8 diary # freedomhack # lummastealer

3/4 Edited to

... Read moreในช่วงไม่กี่ปีที่ผ่านมา เทรนด์มัลแวร์ที่เน้นการขโมยข้อมูลหรือ Infostealer เริ่มพัฒนาขึ้นเรื่อยๆ อย่าง LummaStealer ก็เป็นหนึ่งในมัลแวร์กลุ่มนี้ที่ได้รับความนิยมสูง เนื่องจากความสามารถแฝงตัวผ่านโปรแกรมที่ดูน่าเชื่อถือและเทคนิคการหลอกลวงผู้ใช้ที่แยบยล เช่นวิธีการ ClickFix ที่ใช้หน้าจอแจ้งเตือนปลอมหลอกให้ผู้ใช้ติดตั้งมัลแวร์โดยไม่รู้ตัว จากประสบการณ์ส่วนตัว ผมเคยพบเว็บไซต์ปลอมที่อ้างแจกซอฟต์แวร์แคร็ก เมื่อคลิกดาวน์โหลดจะเจอขั้นตอน Captcha ปลอม ที่ออกแบบมาให้ผู้ใช้ทำตามคำสั่งซึ่งนำไปสู่การดาวน์โหลด CastleLoader ซึ่งทำหน้าที่เป็นฐานในการติดตั้ง LummaStealer ต่อไป ข้อสังเกตคือมัลแวร์จะมีการตรวจสอบสภาพแวดล้อมก่อนทำงานจริง เพื่อเลี่ยงการวิเคราะห์โดย Sandbox หรือ VMware ซึ่งนี่แสดงให้เห็นถึงความชาญฉลาดของมัลแวร์ในการหลีกเลี่ยงการตรวจจับ อีกหนึ่งจุดที่น่าสนใจคือวิธีการสร้างโดเมนปลอมๆ เพื่อหลอกระบบตรวจสอบ DNS ช่วยให้มัลแวร์สามารถฝังตัวอย่างลึกซึ้งและคงทน ด้วยการสร้างทางลัดในโฟลเดอร์ Startup ทำให้มัลแวร์กลับมารันทุกครั้งที่เปิดเครื่องใหม่ นอกจากนี้ยังเน้นขโมยข้อมูลหลากหลายประเภท เช่น รหัสผ่านในเว็บเบราว์เซอร์ ไฟล์คุกกี้ของเซสชัน ข้อมูลจากกระเป๋าเงินคริปโต รวมถึง Token ยืนยันตัวตนสองชั้น (2FA) ซึ่งข้อมูลเหล่านี้มีมูลค่าสูงในตลาดมืด สิ่งที่อยากแนะนำ คือผู้ใช้ควรมีความรู้เกี่ยวกับความปลอดภัยไซเบอร์ขั้นพื้นฐาน รู้จักระวังเว็บไซต์ที่ไม่น่าเชื่อถือโดยเฉพาะที่อ้างแจกแคร็กหรือซอฟต์แวร์เถื่อน และหลีกเลี่ยงการทำตามขั้นตอนที่ดูแปลกหรือขอให้ติดตั้งไฟล์โดยไม่ได้รับการยืนยัน รวมถึงการใช้เครื่องมือรักษาความปลอดภัยที่มีประสิทธิภาพเพื่อช่วยตรวจจับภัยคุกคามให้เร็วขึ้น ในยุคนี้ การรักษาความปลอดภัยข้อมูลส่วนตัวและข้อมูลสำคัญบนเครื่องคอมพิวเตอร์ถือเป็นสิ่งจำเป็นมาก เพราะมัลแวร์ประเภท Infostealer เช่น LummaStealer มีความสามารถสูงในการเจาะข้อมูลอ่อนไหว หากเราไม่ระวัง ก็อาจตกเป็นเหยื่อได้อย่างง่ายดาย การเสริมความรู้และความเข้าใจในเทคนิคหลอกลวงใหม่ๆ จึงกลายเป็นเรื่องสำคัญสำหรับทุกคนที่ใช้งานคอมพิวเตอร์และอินเทอร์เน็ตอย่างไม่ประมาท