Microsoft Threat Intelligence Podcast

Malvertising Campaign Leads to Info Stealers Hosted on Github


Listen Later

In this episode of the Microsoft Threat Intelligence Podcast, host Sherrod DeGrippo is joined by Senior Microsoft Security Researcher Kajhon Soyini to explore the Luma Stealer cryptocurrency mining campaign targeting individual computers as part of a large-scale malvertising campaign. They discuss the sophisticated attack chain, which includes DLLs, clipboard malware, process injection via Explorer.exe, and how this impacted nearly one million devices around the globe.  

Kajhon explains how attackers use registry modifications, WMI event consumers, and obfuscation techniques like non-standard ports and reverse shells to maintain persistence and evade detection. The duo also covers Microsoft's defense efforts and the challenges of tracking down the origins of these attacks. 



In this episode you’ll learn:      

  • Why the attack chain incorporates legacy malware like NetSupport RAT 
  • The overlap between the Luma Stealer and Donarium malware families 
  • How Luma Stealer uses GitHub repositories and redirector networks to deliver malicious payloads 
  •  

    Some questions we ask:     

      

    • Can you explain how the malware uses the “image file execution objects” registry path? 
    • What role does Netcat play in this campaign’s command and control? 
    • Why do people still mine cryptocurrency today, with all the complexities and attack methods? 
    •  

      Resources:  

      View Kajhon Soyini on LinkedIn  

      View Sherrod DeGrippo on LinkedIn  

      Connect with Sherrod and the team at RSAC 

       

      Related Microsoft Podcasts:                   

      • Afternoon Cyber Tea with Ann Johnson 
      • The BlueHat Podcast 
      • Uncovering Hidden Risks     

         

        Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

         

        Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

         

         

        The Microsoft Threat Intelligence Podcast is produced by Microsoft and distributed as part of N2K media network.  

        ...more
        View all episodesView all episodes
        Download on the App Store

        Microsoft Threat Intelligence PodcastBy Microsoft

        • 5
        • 5
        • 5
        • 5
        • 5

        5

        21 ratings


        More shows like Microsoft Threat Intelligence Podcast

        View all
        Risky Business by Patrick Gray

        Risky Business

        364 Listeners

        SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

        SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

        639 Listeners

        Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

        Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

        369 Listeners

        Hacked by Hacked

        Hacked

        180 Listeners

        CyberWire Daily by N2K Networks

        CyberWire Daily

        1,012 Listeners

        Smashing Security by Graham Cluley

        Smashing Security

        316 Listeners

        Click Here by Recorded Future News

        Click Here

        405 Listeners

        Darknet Diaries by Jack Rhysider

        Darknet Diaries

        7,962 Listeners

        Cybersecurity Today by Jim Love

        Cybersecurity Today

        174 Listeners

        CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

        CISO Series Podcast

        190 Listeners

        Hacking Humans by N2K Networks

        Hacking Humans

        316 Listeners

        Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

        Defense in Depth

        77 Listeners

        Cyber Security Headlines by CISO Series

        Cyber Security Headlines

        128 Listeners

        Risky Bulletin by risky.biz

        Risky Bulletin

        43 Listeners

        Hacker And The Fed by Chris Tarbell & Hector Monsegur

        Hacker And The Fed

        169 Listeners