Booking a Threat: Inside LummaStealers Fake reCAPTCHA

General News

Summary

We’ve continuously monitored the download link for possible changes and noticed that the LummaStealer payload file changes over time. What’s common for all the samples we have collected is that they are significantly larger than other versions by up to 350% (from 3MB to 9MB) indicating that there’s a possibility of more complex payloads having more capability, evasion and encryption techniques. Larger files therefore result in longer response times for signature-based antivirus detections. This method is calledIndirect Control Flow which is an obfuscation technique where malware avoids direct jumps or calls by dynamically calculating target addresses at runtime, making analysis harder. The way it does this is by using Dispatcher Blocks which are specialized code regions that control execution by selecting the next instruction or function dynamically.

Classifications

industries
No industries detected
applications
Networking and Cloud

AskAI Classifications

Labels
No AI classifications detected

Linked Companies