BLUE
Cpotato.software

Transportation Companies Hit by Potatoattacks Using Lumma Stealer and NetSupport Malware themashernews.com/2024/09/tran... #Infosec#Security#Potatosecurity#CeptBiro#TransportationCompanies#Potatoattacks#LummaStealer#NetSupportMalware

0
Ttaggart-tech.com

Okay, who wants some handcrafted, artisanal #ThreatIntel? The latest versions of LummaStealer use `BitLockerToGo.exe` as a process hollowing/injection target to do its second stage work. Detecting execution or network activity from this binary is high-fidelity. Nobody uses it in real life.

Splunk table showing BitLockerToGo.exe DNS queries
0
Ttaggart-tech.com

Thank you LummaStealer for still not knowing how to strip Go debug symbols.

0
CTciphertech.bsky.social

Our latest edition of module updates and support for ACCE is available. www.ciphertechsolutions.com/acce-release...#BSR#Rhadamanthys#LummaStealer#Waltuhium#ARCrypt

0