The dark dream of the Lumma malware developer

No ratings

Presented at Virus Bulletin 2024 by

Lumma Stealer has been on the rise since its 1.5-year birthday and nowadays is one of the most prevalent malware families. As evident from its name, the malware's main focus is stealing sensitive data from various software, crypto-wallets, and browsers. In this research, we reveal the details of how the business of the malware operators behind Lumma is built from the inside, discuss its ecosystem, and look inside the malicious code to shed light on what is hidden under the obfuscated parts. We spotted a dispute between Lumma's creator and its ex-coder in a hacking forum. Investigating mutual financial accusations allowed us to reconstruct the structure of the organization responsible for Lumma development, learn the monthly revenues, sources of income, and how the earnings are split between the parties. We also noticed some dirty tricks proposed by Lumma's creator to send its competitors out of business. We continue the presentation by describing the Lumma ecosystem, discussing the estimated number of customers and how the services are provided to them. We also show the unusual methods of malware spreading, including the recently discovered Stargazers network of fake GitHub accounts. Then, we dive into the technical details of recent Lumma versions. The main motto of the Lumma authors is to keep obfuscation to the maximum, lowering the chances of the malware being detected. We show how completely different assembly code – generated by the polymorphic engine – translates to the same high-level logic. We reveal the essentials of network communication and config encryption while providing methods to detect this malware despite all the code differences.