Microsoft Threat Intelligence @threatintel.microsoft.com · Mar 5

The decoded PowerShell script downloads a legitimate but renamed 7-Zip binary that extracts and executes a multi-stage attack chain that includes additional payloads, scheduled tasks, Microsoft Defender exclusions, and exfiltration of stolen machine and network data.

0 likes 1 replies

?

Replies

Microsoft Threat Intelligence · Mar 5

The final-stage payload is a Lumma Stealer component that performs QueueUserAPC()-based code injection into chrome.exe and msedge.exe processes, targeting browser artifacts like Web Data and Login Data, harvesting stored credentials, and exfiltrating them.