# Lumma Stealer Updates

**URL:** https://community.emergingthreats.net/t/lumma-stealer-updates/946
**Category:** Rule Signatures
**Created:** [September 14, 2023, 10:24pm UTC](https://community.emergingthreats.net/t/lumma-stealer-updates/946 "2023-09-14T22:24:44Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)
#### Post date: [September 15, 2023, 5:22am UTC](https://community.emergingthreats.net/t/lumma-stealer-updates/946/2 "2023-09-15T05:22:38Z")

</div>

> [@Lumma Stealer Configuration](https://community.emergingthreats.net/t/lumma-stealer-configuration/685/4):
>
> Hi, we have updated Lumma http post and wrote new rules alert http any any -\> any any (msg: "ET MALWARE [ANY.RUN] Win32/Lumma Stealer Check-In";flow: established, to\_server; http.method;content: "POST"; http.request\_body;content: "act="; depth: 4;content: "&lid="; distance: 0;content: "&j="; distance: 0;content: "&ver="; distance: 0; isdataat: !5, relative; classtype: command-and-control; reference: md5,884478741e7046e6d0788b63c09df89f; reference: url, app.any.run/tasks/409f5138-3853-4910-80d…

---

_[View the full topic](https://community.emergingthreats.net/t/lumma-stealer-updates/946)._
