Leveraging Lumma C2 for Early Threat Detection via DNS
Just a few years ago, threat intelligence data regarding malicious domains offered a protective window while malware was actively spreading. Blocking these malicious domains upon publication provided defense for numerous organizations. However, as threat actor tactics have advanced, much of the potential damage occurs long before these domains are identified and disseminated through open source intelligence (OSINT) or commercially available threat intelligence feeds. Threat actors now prioritize speed, gaining an upper hand, necessitating a responsive defense strategy.
Our DNS Early Detection Program highlights Infoblox’s proprietary techniques that enable the earliest identification of potentially malicious domains. This program presents our recent analysis, comparing public OSINT disclosures of malicious domains with our early identification of these domains as suspicious.
The urgency for swift action is clear. Infoblox’s identification of these suspicious domains enables their blocking weeks or even months earlier than domains published in many industry-wide malicious threat intelligence feeds.
The information indicates that, on average, Infoblox’s threat intelligence feeds for suspicious domains identified 37 Lumma malicious domains a striking 62.1 days earlier than their availability in OSINT. Infoblox’s suspicious domain data can significantly assist our customers in averting a potentially disastrous data breach.
Lumma C2 Stealer, also known as Lumma
Lumma, attributed to the threat actor “Shamel” operating under the pseudonym Lumma, is an information-stealing malware available for purchase on Russian-speaking Dark web forums as malware-as-a-service (MaaS). This accessibility of Lumma through MaaS grants even novices in threat activity an affordable means to access relatively sophisticated and perilous tools.
The packaging and presentation of Lumma, resembling a standard commercial product, can at times seem surreal. Lumma is marketed in various “plans,” offering log upload and analysis. Depending on the selected plan, users can optionally license the use of specialized log and traffic analysis tools. In the “Corporate” version, available at the higher end, there’s a feature allowing the bypassing of numerous proactive defensive protections. The pricing for these plans ranges between $250 to $1,000 U.S.
Typically distributed through spear phishing campaigns with malicious attachments and malvertising campaigns with embedded harmful links, the Lumma payload extracts system data and sensitive information from infected devices. This includes browser data, stored credentials, cryptocurrency data, and even two-factor authentication browser extensions.
Study and Approach
In late September 2023, OSINT released data on 85 Lumma domains. The Infoblox team conducted an analysis to determine if our suspicious domain feeds had earlier identified these malicious domains.
Each malicious domain listed in OSINT underwent thorough research within the Infoblox Dossier portal by our team. We utilized our timeline feature to extract the earliest dates associated with Infoblox’s suspicious designation. Additionally, we retrieved the WHOIS information to provide further context.
The outcomes of our analysis were conclusive:
– Infoblox identified 37 Lumma domains as suspicious an average of 62.1 days before OSINT labeled them as malicious.
– 43% of these suspicious domains were blocked between 72 and 90 days earlier than OSINT’s designation as malicious.
Frequently, OSINT publication dates might be ambiguous or lack precise information. Published articles by reliable third parties may not consistently reflect the accurate availability of each individual domain through OSINT.
To contextualize the efficacy of our suspicious threat intel feeds, we examined WHOIS dates. Our findings showed that among the Lumma C2 infostealer domains, 33 were flagged as suspicious within an average of 2.5 days (60 hours) after the WHOIS domain registration date. WHOIS dates always offer precision, offering an additional viewpoint on the substantial value of our suspicious threat intel feed content.
Mitigating Risk and Maximizing Return on Investment
Infoblox swiftly identifies potentially hazardous DNS domains. Leveraging Infoblox suspicious domain data can diminish risk and enhance the return on investment for your threat intelligence initiative.
Utilizing our exclusive technology for identifying suspicious domains signifies a significant departure from the conventional processes employed in the industry to generate and utilize threat intelligence data. Infoblox’s suspicious domain data equips security operations teams with prompt information, empowering them to more effectively confront and thwart emerging threats before they inflict damage.
The Infoblox Threat Intelligence Group delivers swift access to precise, contextual threat notifications and reports derived from our live research teams. Infoblox enables your team to harness the significant benefits of suspicious domain threat intelligence, ensuring consistent security policy throughout your entire security framework. Infoblox’s threat data mitigates false positives, providing assurance in the entities you’re blocking.





































