Cybercriminals are using the Lumma information-stealing malware, now updated to track mouse movements with trigonometry to detect if it’s running on a real machine or an antivirus sandbox. Available since Dec 2022, Lumma version 4.0 also uses obfuscation, encrypted strings, dynamic configuration files, and crypto enforcement to evade security software. If it detects non-human like behaviour, it halts yet keeps monitoring for human-like activity.

“PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram
PupkinStealer is a C# malware that steals sensitive data, including browser credentials and desktop files, using Telegram for stealthy data exfiltration. Discovered in April 2025,