Campaign record
Lumma Stealer's PNG stego loader
Lumma Stealer delivered by a robot-check lure and a PNG steganography loader
- Status as last assessed
- Active
- First seen
- 2025-10-01
- Last seen
- 2025-11-24
- Indicators
- 19
- Sources
- 1
- Targets
- Windows
- Fake CAPTCHA verification
- Lumma Stealer
Original research
- Huntress2025-11-24Vendor researchFirst account
ClickFix Gets Creative: Malware Buried in Images
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Huntress traced incidents in which a counterfeit human-verification page, served from Cloudflare Pages subdomains, placed an mshta command on the visitor's clipboard and told them to run it from the Windows Run box. The page held its second-stage script XOR-encrypted in a variable and injected it through a blob URL, which frustrates string matching. mshta retrieved a JScript file from a bare IP address written with a hex-encoded second octet; that ran PowerShell in memory, which decrypted a .NET assembly and loaded it reflectively. The assembly carried an AES-encrypted PNG in its manifest resources and rebuilt Donut-packed shellcode out of the red channel of the pixels, XORing each value against 114. Injection into explorer.exe followed, and the unpacked payload was Lumma Stealer. Huntress released a refreshed configuration extractor for the samples it recovered.
Overlap with other campaigns
We compared the 19 indicators in this record — covering 11 distinct registrable domains — against the 43 other published campaigns in this corpus.
AMOS via a fake Spectrum page
2026-08-07No indicator is shared, but the two records use the same registrable domains.
Shared registrable domain (1)
- domain, shown defanged for safety: pages dot dev
A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.
What changed since publication
The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.
- Indicators checked
- 8 of 19
- Checks recorded
- 16
- Checks since publication
- 16
- Never checked
- 11
Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 11 indicators have never been checked by us at all.
Current recorded state
- 8 Unregistered
- 11 Not checked by us
Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Windows Run dialog | 23 of 4452% | T1204.004 |
| PowerShell | 19 of 4443% | T1059.001 |
| Clipboard injection | 15 of 4434% | T1204.004 |
| mshta.exe | 7 of 4416% | T1218.005 |
| PNG pixel-data steganography loader | 2 of 445% | T1027.003 |
All 5 of these mechanisms appear together in 2 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
19 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Lumma Stealer's PNG stego loader”, campaign ID eb151a21, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/eb151a21/lumma-stealer-stego-loader-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.