AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution

March 11, 2025, 3:23 p.m.

Description

A campaign using fake GitHub repositories to distribute SmartLoader and Lumma Stealer malware has been uncovered. The attackers create convincing repositories using AI-generated content to deceive users into downloading malicious files disguised as gaming cheats, cracked software, and system tools. The malware is delivered through obfuscated Lua scripts in ZIP files, exploiting GitHub's trusted reputation to evade detection. Upon execution, SmartLoader facilitates the delivery of Lumma Stealer, which can steal sensitive information like cryptocurrency wallets, 2FA extensions, and login credentials. This campaign demonstrates the evolving tactics of cybercriminals, adapting from using GitHub file attachments to creating entire repositories with AI-assisted deception.

Date

  • Created: March 11, 2025, 12:42 p.m.
  • Published: March 11, 2025, 12:42 p.m.
  • Modified: March 11, 2025, 3:23 p.m.

Indicators

  • dadd4646d32ba0987ad11be623c3153b41b6b704f1e551b6ee745fa1d65d0b9d
  • d0cc55166b23aece72dc41c9d38666023f6046a0c562d8096d19555fab0a3e77
  • 8e8173f0411f8c052959503db6d2cdab651ef122847e2fe61758b50f9fb8a649
  • 7d70e6d7d4fa8d888bd46680aa604dd9f56285dc78c429ac8ab8e4d88266651f
  • 5ce83f99eff295ab626b8f6dacc18a34708a30ac9a95fd23067d71b820283a71
  • 5cbf7acce6e1a18aeab14a2209cf60ecb744b0beedc41585f562846e1fc3e212
  • 57d5c2569a10c07529ed7fb18699095a53d9be342f612b8230e39a48312a6281
  • 3a2f83a62307345bbf273a4292f190636e09110162c7f12a51cb98018c17f27a
  • 2cab00e353e8cd6472c889e944e52d25e0656447fa5af3fc1e95c3b3db32067d
  • 95.164.53.100
  • 213.176.73.80
  • 150.241.105.82
  • 94.156.114.56
  • pasteflawwed.world

Attack Patterns

  • SmartLoader
  • Lumma stealer
  • Water Kurita
  • T1102.002
  • T1059.006
  • T1571
  • T1547.001
  • T1056.001
  • T1555
  • T1573
  • T1204
  • T1027
  • T1041