netcode's User Avatar

@netcode

in /cybersecurity 10 days ago

Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain

Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain - Featured Image

Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain

isc.sans.edu - faviconisc.sans.edu
TLDR

Lumma Stealer infections have shown a pattern of repeatedly adding scheduled tasks that increase traffic to the same C2 domain. The infection retrieves information from a Pastebin link for follow-up activities, using .cc domains for C2 traffic. The infected host generates multiple scheduled tasks with the same trigger and action, leading to increased HTTPS requests and C2 traffic over time.

4Score: 4

1 Comment