EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations

Official source
EudorIA operational summary

What it means

Priority 90/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations. Le misure indicate vanno confrontate con esposizione, identita, segmentazione e capacita di ripristino.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations Release Date May 21, 2025 Alert Code AA25-141B CISA Product Feedback Survey Related topics: Cyber Threats and Response , Malware, Phishing, and Ransomware , Identity Theft and Personal Cyber Threats Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to disseminate known tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated with threat actors deploying the LummaC2 information stealer (infostealer) malware. LummaC2 malware is able to infiltrate victim computer networks and exfiltrate sensitive information, threatening vulnerable individuals’ and organizations’ computer networks across multiple U.S. critical infrastructure sectors. According to FBI information and trusted third-party reporting, this activity has been observed as recently as May 2025. The IOCs included in this advisory were associated with LummaC2 malware infections from November 2023 through May 2025. The FBI and CISA encourage organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of LummaC2 malware. Download the PDF version of this report: AA25-141B Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations (PDF, 1.41 MB ) For a downloadable copy of IOCs, see: AA25-141B STIX XML (XML, 146.54 KB ) AA25-141B STIX JSON (JSON, 300.90 KB ) Technical Details Note: This advisory uses the MITRE ATT&CK ® Matrix for Enterprise framework, version 17. See the MITRE ATT&CK Tactics and Techniques section of this advisory for threat actor activity mapped to MITRE ATT&CK tactics and tech

Indicatori CISA verificabili

135 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 1 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T05:00:47.691123+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
domain-namexayfarer[.]live
domain-nameauthorizev[.]site
domain-namehemispheredodnkkl[.]pw
domain-nametirechinecarpet[.]pw
domain-namelongitudde[.]digital
domain-namelonfgshadow[.]live
domain-nameequatorf[.]run
domain-namehemispherexz[.]top
domain-namelatitudert[.]live
domain-nameclimatologfy[.]top
domain-namequilltayle[.]live
domain-namestarofliught[.]top
domain-namepiratetwrath[.]run
domain-namepomelohgj[.]top
domain-nameowlflright[.]digital
domain-namejawdedmirror[.]run
domain-namenighetwhisper[.]top
domain-namezestmodp[.]top
domain-nameliftally[.]top
domain-nameclarmodq[.]top
domain-namechangeaie[.]top
domain-namesalaccgfa[.]top
domain-namequavabvc[.]top
domain-namefurthert[.]run
domain-nameeasyfwdr[.]digital
domain-namepepperiop[.]digital
domain-namepuerrogfh[.]live
domain-namerambutanvcx[.]run
domain-nameplantainklj[.]run
domain-nameywmedici[.]top
domain-namejrxsafer[.]top
domain-namemetalsyo[.]digital
domain-namenavstarx[.]shop
domain-namerodformi[.]run
domain-nameironloxp[.]live
domain-namegalxnetb[.]today
domain-namestarcloc[.]bet
domain-namespacedbv[.]world
domain-namesteelixr[.]live
domain-nameferromny[.]digital
domain-namecastmaxw[.]run
domain-nameweldorae[.]digital
domain-namesmeltingt[.]run
domain-nameoreheatq[.]live
domain-nametriplooqp[.]world
domain-nametouvrlane[.]bet
domain-namesighbtseeing[.]shop
domain-nameholidamyup[.]today
domain-nameadvennture[.]top
domain-nameesccapewz[.]run
domain-nametravewlio[.]shop
domain-nametargett[.]top
domain-namescenarisacri[.]top
domain-namecitywand[.]live
domain-namecitydisco[.]bet
domain-namemrodularmall[.]top
domain-namelegenassedk[.]top
domain-namejowinjoinery[.]icu
domain-namehtardwarehu[.]icu
domain-namefeatureccus[.]shop
domain-namecjlaspcorne[.]icu
domain-namebugildbett[.]top
domain-namelatchclan[.]shop
domain-nameearthsymphzony[.]today
domain-nameseizedsentec[.]online
domain-namestarrynsightsky[.]icu
domain-namequietswtreams[.]life
domain-namestrawpeasaen[.]fun
domain-namecalmingtefxtures[.]run
domain-namecollapimga[.]fun
domain-nametracnquilforest[.]life
domain-nameforesctwhispers[.]top
domain-namedsfljsdfjewf[.]info
domain-namegovernoagoal[.]pw
domain-namepenetratebatt[.]pw
domain-namehoyoverse[.]blog
domain-namepasteflawwed[.]world
domain-namedecreaserid[.]world
domain-namestormlegue[.]com
domain-namemercharena[.]biz
domain-namenestlecompany[.]pro
domain-nameblast-hubs[.]com
domain-nameblastikcn[.]com
domain-namegeneralmills[.]pro
domain-nameshiningrstars[.]help
domain-namenaturewsounds[.]help
domain-namefriendseforever[.]help
SHA-13b267fa5e1d1b18411c22e97b367258986e871e5
SHA-256ca47c8710c4ffb4908a42bd986b14cddcca39e30bb0b11ed5ca16fe8922a468b
SHA-256a9e9d7770ff948bb65c0db24431f75dd934a803181afa22b6b014fac9a162dab
SHA-2567a35008a1a1ae3d093703c3a34a21993409af42eb61161aad1b6ae4afa8bbb70
SHA-256325daeb781f3416a383343820064c8e98f2e31753cd71d76a886fe0dbb4fe59a
SHA-2564d74f8e12ff69318be5eb383b4e56178817e84e83d3607213160276a7328ab5d
MD5c7610ae28655d6c1bce88b5d09624fef
MD5e05df8ee759e2c955acc8d8a47a08f42
SHA-1b66da4280c6d72adcc68330f6bd793df56a853cb
SHA-2562f31d00feefe181f2d8b69033b382462ff19c35367753e6906ed80f815a7924f
MD54afdc05708b8b39c82e60abe3ace55db
SHA-11239288a5876c09d9f0a67bcfd645735168a7c80
SHA-25619cc41a0a056e503cc2137e19e952814fbdf14f8d83f799aea9b96abff11efbb
domain-namepaleboreei[.]biz
domain-namecomputeryrati[.]site
domain-nameservicedny[.]site
domain-nameseallysl[.]site
domain-namegoalyfeastz[.]site
domain-nameforbidstow[.]site
domain-namefaulteyotk[.]site
domain-namedilemmadu[.]site
domain-namecontemteny[.]site
domain-nameopposezmny[.]site
domain-namereliabledmwqj[.]shop
domain-namewallkedsleeoi[.]shop
domain-namevozmeatillu[.]shop
domain-namestogeneratmns[.]shop
domain-namereinforcenh[.]shop
domain-nameoffensivedzvju[.]shop
domain-namegutterydhowi[.]shop
domain-namefragnantbui[.]shop
domain-namedrawzhotdog[.]shop
domain-nameghostreedmnu[.]shop
domain-namefanlumpactiras[.]pw
domain-nameownerbuffersuperw[.]pw
domain-namemusclefarelongea[.]pw
domain-namepinkipinevazzey[.]pw
domain-namemedicinebuckerrysa[.]pw
domain-namemusicallyageop[.]pw
domain-namefreckletropsao[.]pw
MD58126b593d03a5c9b4f8f0bc25d37ae2eСhrоmеSеtup.exe
SHA-1e8b17d6c7811da116a46b422aa7d86ca6882d673СhrоmеSеtup.exe
SHA-25676e4962b8ccd2e6fd6972d9c3264ccb6738ddb16066588dfcb223222aaa88f3cСhrоmеSеtup.exe
SSDEEP98304:z9iZasQra4ios7RjnRU4UApr2Y5aslkPc3NEjFzyISaS:4Za5+osNbxr5Cc3uzy1СhrоmеSеtup.exe
MD51bcf03b31489b63436d4216249bbf2461bcf03b31489b63436d4216249bbf246.msi
SHA-1e330e5b7f62ca55cb6e6c97406e0b568788069601bcf03b31489b63436d4216249bbf246.msi
SHA-256b287c0bc239b434b90eef01bcbd00ff48192b7cbeb540e568b8cdcdc26f909591bcf03b31489b63436d4216249bbf246.msi
SSDEEP98304:SQCt+uKTFy+XHBflMPzidUtyWmk60KAOmG:DCh0BfMEWt66DG1bcf03b31489b63436d4216249bbf246.msi

Provenance

Allegato ufficiale CISA · 2025-05-21T13:39:01Z

SHA-512: cddaf41bc363a755060ff9ab8d9fd3605012a00f2cc73339f55f784d52d7e688844cc23646c79f7fb869c6640b30f3c3758ff27cac508f235b6b1fbe3c70271d

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
21/05/2025 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1012, T1027, T1036, T1071.001, T1082, T1105, T1106, T1119, T1140, T1217, T1566, T1566.001, T1566.002
Classification
Critical
Stated country
US

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source