Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Popular malware-as-a-service (MaaS) offering Lumma Stealer has been active since 2022. It has been employed, in fact, to target victims in Argentina, Colombia, the U.S., the Philippines, and several other countries worldwide.1
In its latest campaign, the threat actors used fake CAPTCHAs to deliver the stealer. Cybersecurity researchers identified 34 indicators of compromise (IoCs) comprising 27 domains and seven subdomains in their in-depth analysis.2
The WhoisXML API research team dove deeper into the threat aided by our comprehensive DNS intelligence and uncovered potentially connected artifacts, namely: