The LummaC2 v4.0 malware, operating under the Malware-as-a-Service model, uses trigonometry to identify genuine human activity and evade detection by sandboxes used for malware analysis. The malware requires continuous cursor movement to bypass detection. It primarily steals sensitive data including login credentials and credit card details, and its ongoing updates pose a significant threat to financial security.

SparkKitty Monitors Mobile Photo Galleries and Exfiltrates Sensitive Images to C2 Servers
SparkKitty is a cross‑platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrating it to attacker‑controlled


