- Gone Phishing
- Posts
- Lumma Stealer spread via fake cracked software YT vids
Lumma Stealer spread via fake cracked software YT vids

Welcome to Gone Phishing, your daily cybersecurity newsletter thatโs doesnโt need a TV show to hold cybercriminals accountable for their actions ๐ #PostOfficeScandal ๐ฒ๐ข๐ก
Todayโs hottest cybersecurity news stories:
๐ค โLumma Stealerโ spread via fake cracked software YT vids ๐ฅ
๐ฆ Poorly secured MS SQL servers targeted by Turkish hackers ๐จโ๐ป
๐ฏ Babuk Tortilla ransomware foiled by newly-obtained decryptor ๐
Lumma let you finish but Beyonce had one of the best cracked software videos of ALL TIME ๐๐๐ #Kanye
๐จ Alert: YouTube Videos Used to Spread Lumma Stealer Malware! ๐จ
๐ Fortinet FortiGuard Labs recently uncovered a rising threat where cybercriminals are exploiting YouTube to distribute Lumma, an information-stealing malware. ๐พ These YouTube videos often focus on cracked software, luring users with installation guides and hidden malicious URLs. Beware of cracked versions of popular software like Vegas Pro!
How does it work? ๐ก
Users seeking cracked software on YouTube are directed to click a link in the video description, leading to a fake installer on MediaFire. Once downloaded, the ZIP file unleashes a Windows shortcut disguising itself as a setup file. This shortcut triggers the download of a .NET loader from GitHub, loading the Lumma Stealer with anti-virtual machine and anti-debugging checks.
Lumma Stealer Capabilities ๐ซ
This C-written malware, available on underground forums since late 2022, can harvest and send sensitive data to the attacker-controlled server.
Broader Trend ๐
This tactic follows a pattern where cybercriminals exploit YouTube for malware distribution, as seen in previous attacks delivering stealers, clippers, and crypto miners. Bitdefender also warned of stream-jacking attacks on YouTube, emphasising the need for vigilance.
Stay Safe ๐ก๏ธ
Be cautious when navigating YouTube for cracked software, and avoid clicking on suspicious links. Keep your software updated, use reputable security software, and stay informed about emerging cyber threats. Together, we can create a safer digital environment! ๐ป๐

Learn AI in 5 minutes a day. We'll teach you how to save time and earn more with AI. Join 400,000+ free daily readers for trending tools, productivity boosting prompts, the latest news, and more.

Hackers: SQL and Destroy! ๐ฏ๐ฅ๐ฌ
๐ Alert: Financially Motivated Campaign Targets Insecure MS SQL Servers! ๐
๐ Poorly secured Microsoft SQL (MS SQL) servers are under fire in the U.S., European Union, and Latin American (LATAM) regions in an ongoing campaign dubbed RE#TURGENCE. ๐ฏ Researchers at Securonix warn of a dual threat โ compromised host access sale or delivery of ransomware payloads.
Attack Details ๐ซ
Turkish-origin actors execute brute-force attacks on MS SQL servers, using xp_cmdshell for shell command execution. A PowerShell script fetches an obfuscated Cobalt Strike beacon payload, leading to the deployment of Mimic ransomware.
Post-Exploitation Toolkit ๐ผ
The attackers employ AnyDesk for remote access, downloading tools like Mimikatz for credential harvesting and Advanced Port Scanner for reconnaissance. PsExec facilitates lateral movement.
OPSEC Blunder ๐ต๏ธ
Securonix uncovered an Operational Security (OPSEC) misstep โ monitoring clipboard activity revealed the threat actors' Turkish origins and the alias "atseverse," linked to a Steam profile and a Turkish hacking forum called SpyHack.
Security Advice ๐จ
Avoid exposing critical servers directly to the internet. Strengthen your server security to prevent brute-force attacks from external networks.
Stay Informed, Stay Secure! ๐๐ฅ๐ป

๐ฃ Catch of the Day!! ๐๐๐ฆ
๐ The Motley Fool: โFool me once, shame on โ shame on you. Fool me โ you can't get fooled again.โ Good olโ George Dubya ๐ Let us tell whoโs not fooling around though; thatโs the Crรผe ๐ at Motley Fool. Youโd be a fool (alright, enough already! ๐) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! ๐ Kidding aside, if you check out their website theyโve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets ๐ค (LINK)
๐ต Wander: Find your happy place. Cue Happy Gilmore flashback ๐๏ธโณ๐๐๏ธ Mmmm Happy Placeโฆ ๐ So, weโve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, itโs easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ๐๏ธ๐ (LINK)
๐ Digital Ocean: If you build it they will come. Nope, weโre not talking about a baseball field for ghosts โพ๐ป๐ฟ (Great movie, to be fair ๐). This is the Digital Ocean whoโve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website youโll find yourself catching the buzz even if you canโt code (guilty ๐). But if you can and youโre looking for somewhere to test things out or launch something new or simply enhance what youโve got, weโd recommend checking out their services foโ sho ๐ And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! ๐ฟ (LINK)

Holy Guacamole! Thank Bubuk for that! ๐ฎ๐ฅ๐ฏ๐ถ๏ธ๐
๐ก๏ธ Decoding Babuk Tortilla: A Collaborative Cybersecurity Fiesta! ๐๐ฎ
๐จ In a nacho-ordinary victory against cyber threats, experts guac-ed up executable code to decrypt files hit by the notorious Babuk Tortilla ransomware variant! ๐ช๐
Taco 'bout a Global Impact ๐
This ransomware, which kicks like a mule and bites like a crocodile ๐, gained notoriety in 2021, creating a bonafide salsa of chaos globally. 10 different cyber actors, nacho-average troublemakers, turned up the heat with the Babuk toolkit. Cisco Talos detected the Tortilla campaign in October 2021.
Decryptor Evolution ๐
The Babuk Tortilla decryptor, born from leaked source code, got a guac-makeover by Avast Threat Labs. It's a necesito for recovering files spiced with Babuk variants.
User-Friendly Recovery ๐
Avast's Babuk decryptor, as user-friendly as a burrito, lets even non-experts salsa their way to file recovery. Updated versions are ready for download. Hurray!
A Collaborative Triumph ๐ค
Dutch Police, guided by Talos intel, apprehended the Babuk Tortilla threat actor. This victory is a tasty reminder of the power of guac-llaboration ๐ฌ between law enforcement and cybersecurity entities.
ยกGracias Amigos! ๐จ๐ฝโ๐พ
For those embroiled in the Tortilla ransomware mess, the updated Babuk decryptor is as welcome as an ice cold Corona on a hot summerโs day. FYI, it can be found on NoMoreRansom and Avast decryptorsโ pages.
๐ Together We Stand Against Cybercriminals! โ๐๐ป Power To The People, Right On! โ๏ธ๐ธ๐
Always a pleasure to deliver some guac-tastic news... for once! ๐ Stay safe, cyber squad! ๐ก๏ธ๐ฎ

๐๏ธ Extra, Extra! Read all about it!
Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!
The GeekAI: A daily 3 min newsletter on what matters in AI, with all the new AI things coming to market its good to stay ahead of the curve.
Wealthy Primate: Want to earn over $100k a year in IT or cybersecurity? 20 year veteran 'Wealthy Primate' might be able to help you climb that tree ๐๐ด with his stick and banana approach ๐๐
Techspresso: Receive a daily summary of the most important AI and Tech news, selected from 50+ media outlets (The Verge, Wired, Tech Crunch etc)
Let us know what you think!
So long and thanks for reading all the phish!
Give us a rating? |

