Skip to content

Campaign record

Lumma Stealer via GitHub issue mail

Lumma Stealer delivered through abused GitHub issue notifications

Status as last assessed
Active
First seen
2024-09-18
Last seen
2024-09-18
Indicators
12
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Lumma Stealer
  • Abused platform notification email

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Proofpoint dated this activity to 18 September 2024. The operators abused GitHub's own mail: by opening an issue or leaving a comment on a repository they caused GitHub to notify everyone subscribed to it, carrying the attacker's wording inside a message that genuinely originated at the platform. The wording posed as a security alert and pointed readers at github-scanner[.]com, a counterfeit of the site. That page ran an off-the-shelf fake-CAPTCHA kit and padded the clipboard so the victim would not spot the real instruction once it sat in the Run box. Executing it fetched a binary and ended in Lumma Stealer. Around 300 organisations worldwide showed up as affected in Proofpoint's own telemetry. Seven .shop control domains and one Steam profile page are published alongside two payload hashes.

What changed since publication

The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.

Indicators checked
6 of 12
Checks recorded
12
Checks since publication
12
Never checked
6

Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 6 indicators have never been checked by us at all.

Current recorded state

  • 6 Unregistered
  • 6 Not checked by us

Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.

Execution mechanisms

The only execution mechanism any published account describes for this campaign is Windows Run dialog (T1204.004), which 23 of the 44 published campaigns in this corpus also record (52%).

Indicators

12 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenLast seenStateReport an error
domain, shown defanged for safety: github-scanner dot comdomainLure pageAttacker-controlled2024-09-182024-09-18Not checked by usReport an error in domain record ae9b8fd4-b533-4c7d-873a-7da5ba4758d7
url, shown defanged for safety: hxxps colon slash slash github-scanner dot com/l6E dot exeurlDownload URLAttacker-controlled2024-09-182024-09-18Not checked by usReport an error in url record b7dfeb6e-079c-41ec-989b-520011c6e59d
domain, shown defanged for safety: eemmbryequo dot shopdomainCommand and controlAttacker-controlled2024-09-182024-09-18Unregistered2026-08-22Report an error in domain record 1a217582-3a84-40d8-8d10-a81f45c8578b
domain, shown defanged for safety: keennylrwmqlw dot shopdomainCommand and controlAttacker-controlled2024-09-182024-09-18Unregistered2026-08-22Report an error in domain record fe2b9b6a-2251-44c1-82eb-8cac969db7e7
domain, shown defanged for safety: licenseodqwmqn dot shopdomainCommand and controlAttacker-controlled2024-09-182024-09-18Unregistered2026-08-22Report an error in domain record 2650b83f-71b2-4480-bf03-248022b9de17
domain, shown defanged for safety: reggwardssdqw dot shopdomainCommand and controlAttacker-controlled2024-09-182024-09-18Not checked by usReport an error in domain record 30830328-21fd-45f0-b646-57974aa753a9
domain, shown defanged for safety: relaxatinownio dot shopdomainCommand and controlAttacker-controlled2024-09-182024-09-18Unregistered2026-08-22Report an error in domain record e8cc2fe9-a468-410f-80b7-1038d627fd90
domain, shown defanged for safety: tendencctywop dot shopdomainCommand and controlAttacker-controlled2024-09-182024-09-18Unregistered2026-08-22Report an error in domain record e739ab92-4b1e-47b9-a75d-62c138e2fd67
domain, shown defanged for safety: tesecuuweqo dot shopdomainCommand and controlAttacker-controlled2024-09-182024-09-18Unregistered2026-08-22Report an error in domain record 7c5fad33-fc28-492d-b4b0-73e253a64696
url, shown defanged for safety: hxxps colon slash slash steamcommunity dot com/profiles/76561199724331900urlCommand and controlShared platform2024-09-182024-09-18Not checked by usReport an error in url record 62ed966d-be37-42f2-b1ea-dca5f0ce3d31
sha256, shown defanged for safety: d737637ee5f121d11a6f3295bf0d51b06218812b5ec04fe9ea484921e905a207sha256SampleNot yet assessed2024-09-182024-09-18Not checked by usReport an error in sha256 record e51bc842-8415-41aa-80f0-68b649fc8554
sha256, shown defanged for safety: d9ab6cfa60cc75785e31ca9b5a31dae1c33022bdb90cb382ef3ca823c627590dsha256SampleNot yet assessed2024-09-182024-09-18Not checked by usReport an error in sha256 record db2b3e1c-277f-4fd0-b59b-f5a163e33b0f

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account or any overlap with another campaign in this corpus. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “Lumma Stealer via GitHub issue mail”, campaign ID c28a85bb, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/c28a85bb/lumma-stealer-github-notification-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.