The Cybereason Global Security Operations Center (GSOC) has reported on the LummaStealer malware’s advanced evasion techniques. The Russian-developed malware uses the Microsoft HTML Application Host to execute remote code disguised as an innocuous .mp4 file. Furthermore, LummaStealer uses memory injection techniques to bypass Antimalware Scan Interface (AMSI) and uses a fake CAPTCHA page to socially engineer users into triggering code execution.

Ransomware 2.0 How AI-Powered Attacks Are Evolving
Ransomware attacks have evolved with AI, introducing Ransomware 2.0, which combines data theft and encryption with “double” and “triple extortion” tactics, making them harder to