cognitive cybersecurity intelligence

News and Analysis

Search

LummaStealer Exploits Windows Utility to Run Remote Code Disguised as .mp4 File

LummaStealer Exploits Windows Utility to Run Remote Code Disguised as .mp4 File

The Cybereason Global Security Operations Center (GSOC) has reported on the LummaStealer malware’s advanced evasion techniques. The Russian-developed malware uses the Microsoft HTML Application Host to execute remote code disguised as an innocuous .mp4 file. Furthermore, LummaStealer uses memory injection techniques to bypass Antimalware Scan Interface (AMSI) and uses a fake CAPTCHA page to socially engineer users into triggering code execution.

Source: gbhackers.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts