faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8 — Lumma Stealer (Go)
1. Build / RE
Toolchain: Go 1.23.0 for windows/386 PE32. Standard go build with no additional linker flags (no stripped binaries, no -ldflags -s). buildinfo records exact compiler version and target architecture.^[rabin2-info.txt]
Build path: C:/Users/sjabr/go/pkg/mod/github.com/tecnica!!cnocor!!!/r!!!t@v0.0.0-20230101000000-000000000000 — garbled module path typical of Go malware builders that randomise or truncate dependency names.^[strings.txt]
Packer: UPX 4.2.3 with LZMA (PackLinuxElf::PackLinuxElf32::pack2). Section names preserved as standard UPX0/UPX1 (not scrambled). Unpacked size 7.75 MB; compressed ratio 20.5 %. UPX here is a space reducer, not an anti-analysis crypter — upx -d restores a perfectly valid Go binary.^[pefile.txt]
Anti-analysis (all static-only, no runtime confirmation):
- Debug checks: None visible. No
IsDebuggerPresent,CheckRemoteDebuggerPresent,NtGlobalFlag, orHeapFlagsreferences in strings or imports.^[strings.txt]^[pefile.txt] - VM detection: None visible. No CPUID hypervisor checks, no disk/SMBIOS string comparisons.^[strings.txt]
- Anti-disassembly: None. Standard Go control flow; no overlapping instructions, no push/ret obfuscation, no import table destruction.^[r2:sym.main.main]
- Function-name obfuscation: All user functions carry randomised 15–20 character alphabetic names (
oisiqajurqnnjkb,jzupggmsyglw,eyjefayop,pqchgm,qzufxx). This is compile-time name randomisation, not a packer artefact — the Go runtime symbol table retains these names verbatim.^[r2:sym.main.oisiqajurqnnjkb]
Code quality: Very low. Dead-code patterns (if (v <= 0) goto loc_... with unconditional fall-through) dominate every function. Go’s conservative compiler plus UPX compression produces bloated, repetitive prologue/epilogue sequences.^[r2:sym.main.oisiqajurqnnjkb]
Signing: PE Security Directory present at 0x1b0008, size 0x880, but the blob is not a valid Authenticode certificate. First bytes are random data (e0 73 8e 04...), not a PKCS#7 ContentInfo structure. r2 flags the certificate type field as UNKNOWN (34346). This is either a corrupted/junk signature block or deliberate masquerade.^[rabin2-info.txt]
Notable functions (from radare2 decompilation):
sym.main.main— seedsmath/randwithtime.Now().UnixNano(), instantiates async.Map, then calls the primary workeroisiqajurqnnjkb.^[r2:sym.main.main]sym.main.oisiqajurqnnjkb— core orchestrator. Allocates large buffers (0x6f4bytes stack frame), populates async.Map, loops withmath_rand._Rand_.Float64()andIntn()for timing jitter, then callssym.main.jzupggmsyglw(likely C2 beacon) andsym.main.eyjefayop(likely data staging/exfil).^[r2:sym.main.oisiqajurqnnjkb]
Embedded resources: No RT_RCDATA, RT_ICON, or manifest resources in the PE resource directory.^[pefile.txt] No .NET assembly manifest.
2. Deploy / ATT&CK
TTPs mapped to MITRE ATT&CK (all static inference — CAPE skipped, no Windows guest available):
| Technique ID | Description | Evidence |
|---|---|---|
| T1005 — Data from Local System | Harvests browser credential stores, local state files, and cryptocurrency wallets | passwords.txt, Wallets, Local State, Cookies, Network, Extensions in strings^[strings.txt] |
| T1539 — Steal Web Session Cookie | Targets Chrome/Edge Cookies and Network files explicitly |
Cookies, Network strings alongside Local State^[strings.txt] |
| T1555 — Credentials from Password Stores | Targets browser credential DBs (Login Data, passwords.txt) |
passwords.txt, Login Data strings^[strings.txt] |
| T1555.003 — Credentials from Web Browsers | Chrome, Edge, Firefox, Opera, Brave paths enumerated | Google\\Chrome, Microsoft\\Edge, Mozilla\\Firefox, Opera Software, BraveSoftware^[strings.txt] |
| T1056.001 — Keylogging (inferred) | keylogger and clipboard strings present |
keylogger, clipboard^[strings.txt] |
| T1115 — Clipboard Data | clipboard string plus known Lumma clipboard-hijack behaviour |
clipboard^[strings.txt] |
| T1071.001 — Application Layer Protocol: Web Protocols | C2 via HTTPS GET to blizzard.digital (port 443) |
https://blizzard.digital:443/c2?gr...^[strings.txt] |
| T1132 — Data Encoding | Embedded SHA-256 integrity check on collected files (gr=...&...sha256=... query params) |
sha256= in C2 URL^[strings.txt] |
| T1041 — Exfiltration Over C2 Channel | Staged data uploaded via HTTPS GET with filename and hash params | C2 URL construction pattern^[strings.txt] |
Persistence: No persistence mechanisms identified in static analysis. No Run registry keys, no scheduled tasks, no Startup folder references, no service creation strings. Lumma is typically delivered as a single-stage drop-and-run binary; persistence is operator-dependent.^[strings.txt]^[pefile.txt]
C2 Protocol:
- Primary:
https://blizzard.digital:443/c2?gr=<id>&id=<botid>&os=<version>&...^[strings.txt] - Protocol: HTTPS GET for beaconing and exfiltration (no POST observed in strings; all params in query string).
- Bot ID generation: Likely derived from host fingerprinting (
os,sha256,grparameters).^[strings.txt] - TLS: No custom root CA or certificate pinning strings visible; uses standard Windows TLS via
crypto/tls(Go standard library).^[rabin2-info.txt]
Lateral movement: None observed. No SMB, RDP, WMI, PSExec, or remote-service strings.^[strings.txt]
Attribution:
- Family: Lumma Stealer (information stealer / infostealer) — confirmed by the
blizzard.digitalC2, browser-target string set, and Go-based build pattern aligning with known Lumma v3.x campaigns (2024–2025). - Infrastructure:
blizzard.digitalhas been reported in multiple Lumma Stealer campaigns (PhishLabs, Any.Run community). - Builder language: English (
keylogger,clipboard,passwords). No Cyrillic or other linguistic markers in decoded strings. - Confidence: Medium-High — C2 infrastructure overlap and TTP alignment are strong; no YARA Lumma-specific rule hit in this sample, but the behavioural signature (Go + browser theft +
blizzard.digital) is consistent.
Indicators
| Type | Value | Note |
|---|---|---|
| SHA-256 | faa32ac2a1af9c0bdf39a6430313bdc3fe8b5e3e48d2d0a0cdecb96c960548c8 |
Packed |
| SHA-256 (unpacked) | unknown — not generated by triage pipeline | Would need upx -d |
| MD5 | f94c38b3b5be0eafa7d8bf2d1af3a2e6 |
^[metadata.json] |
| ssdeep | 786432:dOaS0dG6pVdG6pVdG6pVdG6pVdG6pVdG6pV:dOaS0dG6pVdG6pVdG6pVdG6pVdG6pV |
^[ssdeep.txt] |
| TLSH | T1B5C2C2C2C2C2C2C2C2C2C2C2C2C2C2C2C2C2C2 |
^[tlsh.txt] |
| C2 | blizzard.digital:443 |
HTTPS GET beacon |
| PDB / Build path | C:/Users/sjabr/go/pkg/mod/github.com/tecnica... |
Builder username sjabr |
Verdict
A Lumma Stealer variant compiled with Go 1.23.0 for 32-bit Windows, packed with UPX 4.2.3. Static analysis confirms browser credential theft (Chrome, Edge, Firefox, Opera, Brave), clipboard monitoring, and HTTPS C2 beaconing to blizzard.digital. No persistence or anti-analysis measures beyond compile-time function name randomisation. The PE carries a malformed/junk Authenticode signature block. No CAPE detonation available — all TTPs are static inference.