Skip to content

Campaign record

Lumma Stealer's PNG stego loader

Lumma Stealer delivered by a robot-check lure and a PNG steganography loader

Status as last assessed
Active
First seen
2025-10-01
Last seen
2025-11-24
Indicators
19
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Lumma Stealer

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

Huntress traced incidents in which a counterfeit human-verification page, served from Cloudflare Pages subdomains, placed an mshta command on the visitor's clipboard and told them to run it from the Windows Run box. The page held its second-stage script XOR-encrypted in a variable and injected it through a blob URL, which frustrates string matching. mshta retrieved a JScript file from a bare IP address written with a hex-encoded second octet; that ran PowerShell in memory, which decrypted a .NET assembly and loaded it reflectively. The assembly carried an AES-encrypted PNG in its manifest resources and rebuilt Donut-packed shellcode out of the red channel of the pixels, XORing each value against 114. Injection into explorer.exe followed, and the unpacked payload was Lumma Stealer. Huntress released a refreshed configuration extractor for the samples it recovered.

Overlap with other campaigns

We compared the 19 indicators in this record — covering 11 distinct registrable domains — against the 43 other published campaigns in this corpus.

  • No indicator is shared, but the two records use the same registrable domains.

    Shared registrable domain (1)

    • domain, shown defanged for safety: pages dot dev

A shared indicator is the same record cited by both campaigns. A shared registrable domain is weaker evidence and is counted separately, because two campaigns can share a registrable simply by renting subdomains from the same platform.

What changed since publication

The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.

Indicators checked
8 of 19
Checks recorded
16
Checks since publication
16
Never checked
11

Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 11 indicators have never been checked by us at all.

Current recorded state

  • 8 Unregistered
  • 11 Not checked by us

Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Windows Run dialog23 of 4452%T1204.004
PowerShell19 of 4443%T1059.001
Clipboard injection15 of 4434%T1204.004
mshta.exe7 of 4416%T1218.005
PNG pixel-data steganography loader2 of 445%T1027.003

All 5 of these mechanisms appear together in 2 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

19 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentFirst seenStateReport an error
domain, shown defanged for safety: 1e442295 dot consent-verify dot pages dot devdomainLure pageShared platform2025-10-01Not checked by usReport an error in domain record fd3577dd-b31b-4507-b32b-cfbe36e19a5a
domain, shown defanged for safety: 3b4ce6c9 dot consent-verify dot pages dot devdomainLure pageShared platform2025-10-01Not checked by usReport an error in domain record 383aa4b1-c338-4fb8-b268-d6891a60d4d9
domain, shown defanged for safety: 3e6eb645 dot consent-verify dot pages dot devdomainLure pageShared platform2025-10-01Not checked by usReport an error in domain record 49c86e02-8c32-4750-8c20-df0170069f06
domain, shown defanged for safety: 5df43170 dot consent-verify dot pages dot devdomainLure pageShared platform2025-10-01Not checked by usReport an error in domain record 5fbf8013-0087-4612-8573-5d195ce18ee8
domain, shown defanged for safety: 6b04000 dot consent-verify dot pages dot devdomainLure pageShared platform2025-10-01Not checked by usReport an error in domain record e862a5a2-023e-49f6-939e-f7ddf76ec3a7
domain, shown defanged for safety: d9e71335 dot consent-verify dot pages dot devdomainLure pageShared platform2025-10-01Not checked by usReport an error in domain record 74d4f9f3-0d7f-452a-a302-ad1eabfe8f68
domain, shown defanged for safety: f6b04000 dot consent-verify dot pages dot devdomainLure pageShared platform2025-10-01Not checked by usReport an error in domain record 5b3de2cb-ab39-4e9e-bc00-47820eb21eea
url, shown defanged for safety: hxxp colon slash slash 81 dot 90 dot 29 dot 64/ebc/rps dot gzurlDownload URLNot yet assessed2025-10-01Not checked by usReport an error in url record 02cff35f-8521-4a5d-b458-7cf81fdba31f
ip, shown defanged for safety: 81 dot 90 dot 29 dot 64ipPayload hostNot yet assessed2025-10-01Not checked by usReport an error in ip record fc1ebe28-6e0e-4d82-957a-05a1e670dfe5
domain, shown defanged for safety: bendavo dot sudomainCommand and controlAttacker-controlled2025-10-01Unregistered2026-08-22Report an error in domain record 52b2fcf7-2607-425a-9ae0-87e0192fc9ab
domain, shown defanged for safety: conxmsw dot sudomainCommand and controlAttacker-controlled2025-10-01Unregistered2026-08-22Report an error in domain record f364ae70-c98c-4734-bb74-952ce594d40d
domain, shown defanged for safety: exposqw dot sudomainCommand and controlAttacker-controlled2025-10-01Unregistered2026-08-22Report an error in domain record fb7e4256-4969-4adb-a381-b11c8ba010dc
domain, shown defanged for safety: hypudyk dot shopdomainCommand and controlAttacker-controlled2025-10-01Not checked by usReport an error in domain record 1137724e-3753-416e-a4bc-e0b4efdaf27e
domain, shown defanged for safety: narroxp dot sudomainCommand and controlAttacker-controlled2025-10-01Unregistered2026-08-22Report an error in domain record 7083cf4e-ca18-41d5-9327-96b7f872c299
domain, shown defanged for safety: ozonelf dot sudomainCommand and controlAttacker-controlled2025-10-01Unregistered2026-08-22Report an error in domain record e4de2fe9-46d9-4031-8a5a-8d38876e3c1a
domain, shown defanged for safety: squatje dot sudomainCommand and controlAttacker-controlled2025-10-01Unregistered2026-08-22Report an error in domain record 2231f205-500d-4265-9dda-547f1c14cb2c
domain, shown defanged for safety: squeaue dot sudomainCommand and controlAttacker-controlled2025-10-01Unregistered2026-08-22Report an error in domain record 03431c3c-7288-43d2-87e5-9a85bd4f1eaf
domain, shown defanged for safety: vicareu dot sudomainCommand and controlAttacker-controlled2025-10-01Unregistered2026-08-22Report an error in domain record 1200da88-3bbc-476c-805b-0739be9aad3e
url, shown defanged for safety: hxxp colon slash slash corezea dot com/ebcurlStagingAttacker-controlled2025-10-01Not checked by usReport an error in url record 426f91a4-85d1-40d4-8d7a-890cd38097aa

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “Lumma Stealer's PNG stego loader”, campaign ID eb151a21, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/eb151a21/lumma-stealer-stego-loader-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.