Campaign record
Lumma Stealer via film piracy sites
Lumma Stealer served by film-piracy malvertising redirectors
- Status as last assessed
- Active
- First seen
- 2025-04-02
- Last seen
- 2025-04-02
- Indicators
- 1
- Sources
- 1
- Targets
- Windows
- Pirated film streaming site
- Lumma Stealer
- Malvertising
Original research
- Microsoft Threat Intelligence2025-08-21Vendor researchFirst account
Think before you Click(Fix): Analyzing the ClickFix social engineering technique
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Microsoft describes a chain running in April 2025 that fed on people hunting for films to watch without paying. Touching the player on those sites — a press of the play control was enough — threw open new tabs of scam pages, and one of them was a ClickFix lure whose end result was Lumma Stealer on the machine. Volume is what marks the cluster out: on a single day the redirectors could push tens of thousands, possibly hundreds of thousands, of separate visitors into those pages. Its other habit is renaming the intermediate HTA scripts to look like media, with endings such as .mp3, .mp4 or .ogg, so a downloaded file reads as a song or a clip rather than something executable. The host named in the pasted command is recorded as tesra[.]shop, seen on 2 April 2025.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Windows Run dialog | 23 of 4452% | T1204.004 |
| mshta.exe | 7 of 4416% | T1218.005 |
Both of these mechanisms appear together in 5 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
1 indicator, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
| Indicator | Type | Role | Assessment | First seen | Last seen | Report an error |
|---|---|---|---|---|---|---|
| domain, shown defanged for safety: tesra dot shop | domain | Payload host | Not yet assessed | 2025-04-02 | 2025-04-02 | Report an error in domain record 3aa77907-1376-45da-98cc-ef7561004c4b |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Lumma Stealer via film piracy sites”, campaign ID e01a09c6, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/e01a09c6/lumma-stealer-clickfix-malvertising
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.