# Lumma Stealer Updates

**URL:** https://community.emergingthreats.net/t/lumma-stealer-updates/946
**Category:** Rule Signatures
**Created:** [September 14, 2023, 10:24pm UTC](https://community.emergingthreats.net/t/lumma-stealer-updates/946 "2023-09-14T22:24:44Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)
#### Post date: [September 14, 2023, 10:24pm UTC](https://community.emergingthreats.net/t/lumma-stealer-updates/946/1 "2023-09-14T22:24:44Z")

</div>

Lumma Stealer announced an update at September 14th, announcing a new exfiltration method on its builds.

Endpoints /c2sock and /c2conf were changed by POST request to a common endpoint for both purposes, /api via form parameters.

 ![F6BLLBWWwAAV4cz](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/be10e52f1b5085b91e87d78f8d43efdd548e1ba9.png)

 ![F6BMfckWUAASD3k](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/880d676cd3ca33ca4d19047d75ccd7e98b026fa1.png)

rule detection is currently 0, altough lumma builds are attempting to bypass sandbox analysis. I believe new rules has to be written in order to keep track on this major threat.

Failed detonation (Detection by memory dumps)  
[Analysis https://randsoms.click Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/1ce748d0-88c4-472d-b428-cf16a54bc5b1/)

PCAP extracted from [Triage | Malware sandboxing report by Hatching Triage](https://tria.ge/230914-1b6mzshg77)

Thanks in advance

---

<div class="post-metadata">

### Author: ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)
#### Post date: [September 15, 2023, 5:22am UTC](https://community.emergingthreats.net/t/lumma-stealer-updates/946/2 "2023-09-15T05:22:38Z")

</div>

> [@Lumma Stealer Configuration](https://community.emergingthreats.net/t/lumma-stealer-configuration/685/4):
>
> Hi, we have updated Lumma http post and wrote new rules alert http any any -\> any any (msg: "ET MALWARE [ANY.RUN] Win32/Lumma Stealer Check-In";flow: established, to\_server; http.method;content: "POST"; http.request\_body;content: "act="; depth: 4;content: "&lid="; distance: 0;content: "&j="; distance: 0;content: "&ver="; distance: 0; isdataat: !5, relative; classtype: command-and-control; reference: md5,884478741e7046e6d0788b63c09df89f; reference: url, app.any.run/tasks/409f5138-3853-4910-80d…

---

<div class="post-metadata">

### Author: ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)
#### Post date: [September 15, 2023, 3:35pm UTC](https://community.emergingthreats.net/t/lumma-stealer-updates/946/3 "2023-09-15T15:35:20Z")

</div>

Thanks @g0njxa - I took a look this morning and @Jane0sint ‘s new sigs will catch the new exfiltration method. I’ll get those in today’ release 🤠

Here are the signature ID’s:

```auto
2048093 - ET MALWARE [ANY.RUN] Win32/Lumma Stealer Check-In 
2048094 - ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration
```
