Tracking LummaC2 Infrastructure with Cats
The US Department of Justice and Microsoft disrupted LummaC2 infostealing-malware through domain seizures, taking down over 2,300 associated domains. The FBI and CISA released an advisory detailing LummaC2's tactics and indicators of compromise, including 114 domains. Analysis of these domains revealed common registration patterns, such as using Eastern European names and specific mail server hostnames. Notably, several domains featured an 'About Cats' landing page, with 58 additional domains sharing this characteristic and having high risk scores. These domains are suspected of distributing LummaC2 and other malware strains. Despite the takedown efforts, 41 of these domains remain active, highlighting the need for continued vigilance against LummaC2 infrastructure.
Pulse ID: 6839003a3028827e1ebbfb1a
Pulse Link: https://otx.alienvault.com/pulse/6839003a3028827e1ebbfb1a
Pulse Author: AlienVault
Created: 2025-05-30 00:47:54
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CISA #CyberSecurity #EasternEurope #Europe #FBI #ICS #InfoSec #LummaC2 #Mac #Malware #Microsoft #OTX #OpenThreatExchange #RAT #bot #AlienVault