Tag: LummaC2

Hackers Target Python Developers with Fake “Crytic-Compilers” Package on PyPI
News

Hackers Target Python Developers with Fake “Crytic-Compilers” Package on PyPI

A malicious Python package that was posted to the Python Package Index (PyPI) repository with the intention of delivering the information stealer Lumma (also known as LummaC2) has been found by cybersecurity researchers. The package in question is called crytic-compilers, which is a misspelling of the actual crytic-compile library. Before PyPI maintainers removed the fraudulent package, it had been downloaded 441 times. According to Sonatype security researcher Ax Sharma, "the counterfeit library is interesting in that it aligns its version numbers with the real library, in addition to being named after the legitimate Python utility, 'crytic-compile." The fake "crytic-compilers" version starts at 0.3.11 and ends there, giving the impression that this is a newer version of the com...
Beware: Fake Browser Updates Deliver BitRAT and Lumma Stealer Malware
News

Beware: Fake Browser Updates Deliver BitRAT and Lumma Stealer Malware

Information stealer viruses like BitRAT and Lumma Stealer (also known as LummaC2), as well as remote access trojans (RATs), are being distributed through phony web browser upgrades. The well-known SocGholish malware is among the many malware outbreaks that have been caused by fake browser upgrades, according to a recent analysis from cybersecurity company eSentire. "We saw similar bogus update procedures being used to disseminate FakeBat in April 2024. Potential targets visit a website that has been planted with booby-trapped JavaScript code that directs users to a fake browser update page ("chatgpt-app[.]cloud"). This is where the attack chain starts. A download link to a ZIP archive file ("Update.zip") that is hosted on Discord and downloaded automatically to the victim's devic...