I am very sceptical about everything that is detected as Lumma Stealer since September 2025, when the administration of Lumma decided to vanish. Since that moment, everything related to Lumma should be thougth twice or even 3 times before associating to them.
hey @g0njxa - Thanks for bringing this to our attention! This week I’ve been talking to some of the researchers who handle our Lumma automation and config extraction to get some insight into how these are handled.
After reviewing a few samples we found the config extracted will sometimes contain at least one domain which is definitely Lumma which results in the classification, but this may be residual from the actor not cleaning up the config completely before new campaigns. This said, we only reviewed a limited number of samples so it’s not a complete view.
We will keep an eye out and update our automation process to handle Aura going forward based on telemetry we see. I was curious and found that the trend of Lumma (DNS) sigs being released drops off significantly between July and October which correlates with what you’ve seen.