Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitydefense-evasion-methodcybercrime-service-ecosystemcommand-and-control-method

Resurgence of Windows infostealers using stealth packaging and social-engineering lures

Updated 3mo agoFirst seen Feb 12, 20262 sources

Threat researchers reported renewed activity from Windows credential-stealing malware that is designed to evade detection and rapidly scale infections. CYFIRMA described LTX Stealer as being delivered via a heavily obfuscated installer that abuses trusted developer and packaging tools—using Inno Setup to masquerade as legitimate software, embedding a full Node.js runtime, and compiling malicious JavaScript into bytecode to hinder reverse engineering. The installer reportedly contains an unusually large encrypted archive (hundreds of MB) intended to frustrate static scanning, and drops a payload (e.g., updater.exe) that functions as the bundled Node.js runtime used to execute the stealer logic.

Separately, reporting citing Bitdefender said Lumma Stealer has returned “back at scale” after prior law-enforcement disruption of its infrastructure, rebuilding domains and command-and-control capacity to resume widespread credential and data theft. Lumma’s malware-as-a-service ecosystem continues to rely on high-conversion distribution methods, including lure sites offering pirated/cracked content and the ClickFix social-engineering technique that tricks users into infecting their own systems, underscoring how infostealer operators are combining resilient infrastructure with user-driven execution to maintain volume despite takedowns.

Share:
Resurgence of Windows infostealers using stealth packaging and social-engineering lures
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 12, 20264mo ago

LTX Stealer is assessed as a low-cost stealer-as-a-service

The LTX operation was assessed as a stealer-as-a-service offering backed by Supabase infrastructure fronted by Cloudflare and advertised with inexpensive subscription tiers. The pricing and infrastructure suggested the malware was intended for broad criminal distribution.

CYFIRMA reports Node.js-based LTX Stealer campaign

CYFIRMA disclosed a Windows credential-theft campaign involving LTX Stealer, which uses a heavily obfuscated Inno Setup installer and a bundled Node.js runtime to evade antivirus detection. The malware steals browser credentials, cookies, session tokens, and cryptocurrency wallet data.

Feb 11, 20264mo ago

Renewed Lumma campaigns use ClickFix fake CAPTCHA lures

Current Lumma campaigns heavily rely on ClickFix social engineering, including fake CAPTCHA pages that trick users into pasting malicious commands into Windows Terminal. The infection chain then deploys loader malware followed by Lumma Stealer.

Microsoft identifies Lumma as a go-to tool for crime groups

Microsoft described Lumma as a preferred tool used by multiple cybercrime groups, including Scattered Spider. This attribution highlighted the malware's broad adoption in criminal operations.

Lumma operators rebuild and resume global distribution

Following the May law-enforcement action, researchers said Lumma's operators rapidly rebuilt their infrastructure and returned to widespread activity. The renewed campaigns again targeted users globally.

Lumma infects nearly 395,000 Windows systems in two months

At an unspecified point before the 2026 reporting, Lumma Stealer infected almost 395,000 Windows systems over a two-month period. The scale established it as a major infostealer threat used by multiple criminal groups.

May 1, 20251y ago

International law enforcement disrupts Lumma infrastructure

Authorities carried out a takedown of Lumma infrastructure, seizing thousands of domains and related systems in an international disruption operation. The action temporarily hobbled the malware operation.

Jan 1, 20224y ago

Lumma Stealer is advertised on Russian-speaking crime forums

Lumma Stealer was first promoted in Russian-speaking cybercrime forums as a malware-as-a-service offering. It later developed into a cloud-based infostealer operation with extensive lure and command-and-control infrastructure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Affected products
2 linked
CloudflareWindows
Organizations
6 linked
Microsoft CorporationCloudflareSupabaseCYFIRMAGoogleBitdefender
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.