NetDefend IPS
IPS Advisories
NetDefend
Anti-Virus
Anti-Virus Advisories
NetDefend Web Content Filtering
NetDefend IP Reputation
NetDefend Update Center
IPS History
Jun 12, 2025
Jun 05, 2025
May 29, 2025
May 22, 2025
May 16, 2025
Anti-Virus History
Feb 12, 2022
Jan 06, 2022
Oct 23, 2021
Aug 29, 2021
Aug 23, 2021







Home > NetDefend Live > NetDefend IPS Service
NetDefend IPS Service
Print
Advisory ID
49162
Name
MALWARE.CYPHERIT.CRYPTER.USED.IN.LUMMA.STEALER.DISTRIBUTION.A
IPS Signature
Advanced IPS Signature
IPS Group
IPS / MALWARE / GENERAL
Issued
Jun 12, 2025
Description
The infection chain for the Lumma Stealer variant begins with a lure page linking to a password-protected 7-zip archive, often disguised as cracked software. This archive contains a Nullsoft installer, leveraging AutoIt scripts and NSIS self-extracting archives for initial infection. A variant of the CypherIT crypter is used to drop a batch file, which then constructs a malicious AutoIt script containing embedded shell code. This script decrypts and decompresses the Lumma Stealer payload, injecting it into a suspended explorer.exe process via process hollowing, with some instances also delivering a cryptocurrency-stealing "clipper" payload.
Enter your details in the box below to receive an email each time we post a new issue of our newsletter.







Jun 17, 2025