Threat reportMalwareTL-2026-0773

LummaStealer (V34XV4) Distributed via Fake Game-Update Comments on itch.io Linking to Patreon-Hosted nexe Loaders

highACTIVE

LummaStealer (V34XV4) Distributed via Fake Game-Update (TL-2026-0773), also tracked as Lumma Stealer itch.io/Patreon fake game-update campaign, is a high-severity malware campaign, first published 2026-06-10. It has no confirmed attribution, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-0773

Threat ID
TL-2026-0773
Also known as
Lumma Stealer itch.io/Patreon fake game-update campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
gaming, technology, consumer, software-development
Target regions
Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in LummaStealer (V34XV4) Distributed via Fake Game-Update

Malware and tooling: Lumma Stealer - S1213, Win64.Trojan-Stealer.LummaStealer.V34XV4, nexe

How LummaStealer (V34XV4) Distributed via Fake Game-Update works

A single threat actor distributes the LummaStealer (LummaC2) infostealer by spamming fake game-update comments on legitimate itch.io games that link to a malicious 'Updated Version.zip' hosted on Patreon. The archive's game.exe is a nexe-compiled Node.js PE that runs obfuscated JavaScript (mains.js) to reflectively load a native DLL (modules.node) via the N-API export 'PodstilkaBidena', executing a Base64-encoded LummaStealer payload behind six layers of VM/sandbox-evasion checks.

G DATA (Josemaria Grana) documented an active, ongoing malware campaign abusing the trust ecosystem of the indie-game platform itch.io and the creator-funding platform Patreon to distribute the LummaStealer (LummaC2) information stealer. The operator registers numerous freshly-created itch.io accounts and posts templated spam comments on the comment sections of legitimate games, impersonating official updates and directing victims to a Patreon URL that downloads an archive named 'Updated Version.zip'. Most files in the archive are benign decoys; the malicious component is 'game.exe', a 78.21 MiB Node.js application compiled to a Windows PE using the nexe packer.

On execution, game.exe runs obfuscated JavaScript (recovered as mains.js). The script first applies an aggressive six-level anti-analysis/sandbox-evasion gate: (1) terminate if system memory is under 4 GB or CPU cores are 2 or fewer; (2) compare os.userInfo() against a blacklist of 53+ analyst/sandbox usernames such as 'sandbox', 'vmware', 'malware', 'virus', 'test user', 'george', and 'wdagutilityaccount'; (3) enumerate running processes via 'tasklist /fo csv' and bail if any of 80+ analysis tools (IDA, Wireshark, Frida, OllyDbg, x64dbg, Burp Suite, etc.) are present; (4) detect virtual GPUs via 'wmic path win32_VideoController get name /value' (matching 'vmware svga 3d', 'virtualbox graphics adapter', 'microsoft basic display adapter'); (5) terminate if the display refresh rate read via 'wmic path Win32_VideoController get CurrentRefreshRate /value' is below 29 Hz; (6) detect virtual disks via 'wmic diskdrive get model /value' (matching 'vbox', 'vmware', 'virtio', 'qemu hardiskk'). Newer samples substitute PowerShell CIM cmdlets (Get-CimInstance Win32_VideoController) as fallback evasion methods, and all child commands are spawned hidden with 'windowsHide: true'.

If the environment passes the checks, a Base64-encoded LummaStealer payload is dropped to the %temp% directory as 'modules.node', a native DLL exporting napi_register_module_v1 and node_api_module_get_api_version_v1. Inside node_api_module_get_api_version_v1, the loader uses the Node-API functions napi_create_function and napi_set_named_property to register a C/C++ function named 'PodstilkaBidena' as a JavaScript property — a reflective code-loading technique that executes the LummaStealer payload inside the Node.js host process. LummaStealer then harvests browser credentials, cookies, autofill, cryptocurrency-wallet data, and other secrets, and can stage follow-on malware, exfiltrating over its C2 channel.

The campaign is attributed to a single actor on the strength of consistent tradecraft: continuous rotation of newly-created itch.io accounts that survive platform removals, distinct Patreon URLs per account that yield different encoded JavaScript variants, and per-sample mutation of variable/function names and encoding methods to delay signature detection. LummaStealer is a long-running malware-as-a-service offering (sold on underground forums since mid-2022, subscriptions from ~$250/month up to a ~$20,000 source-code option) that survived a major May 2025 Microsoft/DOJ takedown of ~2,300 C2 domains and has since rebuilt to pre-takedown infection levels, increasingly delivered via loaders such as CastleLoader and ClickFix social engineering. This itch.io/Patreon vector is a fresh distribution TTP for the family.

MITRE ATT&CK techniques used in TL-2026-0773

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts; T1620 Reflective Code Loading

Discovery

T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1497 Virtualization/Sandbox Evasion; T1518 Software Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1132 Data Encoding

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1608 Stage Capabilities

Affected products and versions in LummaStealer (V34XV4) Distributed via Fake Game-Update

  • Microsoft — Windows
    Vulnerable versions: Windows 10 (x64); Windows 11 (x64)
  • itch.io — itch.io game/comment platform
    Vulnerable versions: abused as social-engineering distribution channel
  • Patreon — Patreon
    Vulnerable versions: abused as malicious archive hosting

Remediation for LummaStealer (V34XV4) Distributed via Fake Game-Update

Immediate actions

  • Block and alert on the published SHA256 hashes (Updated Version.zip, game.exe, mains.js, modules.node, LummaStealer payload) across EDR and email/web gateways
  • Treat any 'Updated Version.zip' or game.exe downloaded from a Patreon URL referenced in an itch.io comment as malicious; do not execute
  • Hunt for a native DLL named modules.node written to %temp% and for processes loading it via Node-API
  • Alert on game/Node.js-named executables spawning tasklist and wmic videocontroller/diskdrive enumeration in quick succession

Workarounds

  • Disable execution of binaries from user Downloads/temp directories where feasible
  • Use browsers/password managers that bind cookies and credentials to the device to reduce reuse of stolen tokens

Longer-term hardening

  • Deploy EDR with behavioral detection for reflective/Node-API code loading and sandbox-evasion command bursts
  • Educate game developers and players that itch.io comments and Patreon are not official update-delivery channels
  • Restrict execution of unsigned single-file Node.js/nexe-packed binaries via application control (WDAC/AppLocker)
  • Enforce phishing-resistant MFA and short session lifetimes to blunt cookie/session theft by infostealers

Timeline of LummaStealer (V34XV4) Distributed via Fake Game-Update

  • LummaStealer (LummaC2) first advertised for sale on underground forums as a malware-as-a-service infostealer (since at least mid-2022).
  • Microsoft begins a measurement window in which it identifies over 394,000 Windows computers globally infected by Lumma malware (through 2025-05-16).
  • Microsoft DCU and the US DOJ disrupt LummaC2, seizing/blocking ~2,300 malicious C2 domains and the central command infrastructure and marketplaces.
  • After June 2025 Lumma operators diversify hosting away from the prior Cloudflare-resolving pattern across multiple providers, and infection volumes rebuild toward pre-takedown levels.
  • G DATA (Josemaria Grana) publishes analysis of the itch.io/Patreon fake-game-update campaign delivering LummaStealer variant V34XV4 via nexe-compiled loaders, with SHA256 IOCs and detections.
  • Security press (Cyberpress, GBHackers, Hackread) report on the itch.io/Patreon Lumma distribution campaign and its reflective Node-API loading technique.
  • LummaStealer infections surge as the operation increasingly leans on the CastleLoader loader and ClickFix social-engineering delivery (Dec 2025-Jan 2026).
  • Threadlinqs documents TL-2026-0773 with full IOC set, MITRE mapping, and detection guidance for the itch.io/Patreon LummaStealer campaign.

Sources cited for LummaStealer (V34XV4) Distributed via Fake Game-Update

Detection coverage for TL-2026-0773

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0773 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats