Threat reportMalwareTL-2026-0773
LummaStealer (V34XV4) Distributed via Fake Game-Update Comments on itch.io Linking to Patreon-Hosted nexe Loaders
LummaStealer (V34XV4) Distributed via Fake Game-Update (TL-2026-0773), also tracked as Lumma Stealer itch.io/Patreon fake game-update campaign, is a high-severity malware campaign, first published 2026-06-10. It has no confirmed attribution, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-0773
- Threat ID
- TL-2026-0773
- Also known as
- Lumma Stealer itch.io/Patreon fake game-update campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- gaming, technology, consumer, software-development
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in LummaStealer (V34XV4) Distributed via Fake Game-Update
Malware and tooling: Lumma Stealer - S1213, Win64.Trojan-Stealer.LummaStealer.V34XV4, nexe
How LummaStealer (V34XV4) Distributed via Fake Game-Update works
A single threat actor distributes the LummaStealer (LummaC2) infostealer by spamming fake game-update comments on legitimate itch.io games that link to a malicious 'Updated Version.zip' hosted on Patreon. The archive's game.exe is a nexe-compiled Node.js PE that runs obfuscated JavaScript (mains.js) to reflectively load a native DLL (modules.node) via the N-API export 'PodstilkaBidena', executing a Base64-encoded LummaStealer payload behind six layers of VM/sandbox-evasion checks.
G DATA (Josemaria Grana) documented an active, ongoing malware campaign abusing the trust ecosystem of the indie-game platform itch.io and the creator-funding platform Patreon to distribute the LummaStealer (LummaC2) information stealer. The operator registers numerous freshly-created itch.io accounts and posts templated spam comments on the comment sections of legitimate games, impersonating official updates and directing victims to a Patreon URL that downloads an archive named 'Updated Version.zip'. Most files in the archive are benign decoys; the malicious component is 'game.exe', a 78.21 MiB Node.js application compiled to a Windows PE using the nexe packer.
On execution, game.exe runs obfuscated JavaScript (recovered as mains.js). The script first applies an aggressive six-level anti-analysis/sandbox-evasion gate: (1) terminate if system memory is under 4 GB or CPU cores are 2 or fewer; (2) compare os.userInfo() against a blacklist of 53+ analyst/sandbox usernames such as 'sandbox', 'vmware', 'malware', 'virus', 'test user', 'george', and 'wdagutilityaccount'; (3) enumerate running processes via 'tasklist /fo csv' and bail if any of 80+ analysis tools (IDA, Wireshark, Frida, OllyDbg, x64dbg, Burp Suite, etc.) are present; (4) detect virtual GPUs via 'wmic path win32_VideoController get name /value' (matching 'vmware svga 3d', 'virtualbox graphics adapter', 'microsoft basic display adapter'); (5) terminate if the display refresh rate read via 'wmic path Win32_VideoController get CurrentRefreshRate /value' is below 29 Hz; (6) detect virtual disks via 'wmic diskdrive get model /value' (matching 'vbox', 'vmware', 'virtio', 'qemu hardiskk'). Newer samples substitute PowerShell CIM cmdlets (Get-CimInstance Win32_VideoController) as fallback evasion methods, and all child commands are spawned hidden with 'windowsHide: true'.
If the environment passes the checks, a Base64-encoded LummaStealer payload is dropped to the %temp% directory as 'modules.node', a native DLL exporting napi_register_module_v1 and node_api_module_get_api_version_v1. Inside node_api_module_get_api_version_v1, the loader uses the Node-API functions napi_create_function and napi_set_named_property to register a C/C++ function named 'PodstilkaBidena' as a JavaScript property — a reflective code-loading technique that executes the LummaStealer payload inside the Node.js host process. LummaStealer then harvests browser credentials, cookies, autofill, cryptocurrency-wallet data, and other secrets, and can stage follow-on malware, exfiltrating over its C2 channel.
The campaign is attributed to a single actor on the strength of consistent tradecraft: continuous rotation of newly-created itch.io accounts that survive platform removals, distinct Patreon URLs per account that yield different encoded JavaScript variants, and per-sample mutation of variable/function names and encoding methods to delay signature detection. LummaStealer is a long-running malware-as-a-service offering (sold on underground forums since mid-2022, subscriptions from ~$250/month up to a ~$20,000 source-code option) that survived a major May 2025 Microsoft/DOJ takedown of ~2,300 C2 domains and has since rebuilt to pre-takedown infection levels, increasingly delivered via loaders such as CastleLoader and ClickFix social engineering. This itch.io/Patreon vector is a fresh distribution TTP for the family.
MITRE ATT&CK techniques used in TL-2026-0773
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1564 Hide Artifacts; T1620 Reflective Code Loading
Discovery
T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1497 Virtualization/Sandbox Evasion; T1518 Software Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1132 Data Encoding
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1608 Stage Capabilities
Affected products and versions in LummaStealer (V34XV4) Distributed via Fake Game-Update
- Microsoft — Windows
Vulnerable versions: Windows 10 (x64); Windows 11 (x64) - itch.io — itch.io game/comment platform
Vulnerable versions: abused as social-engineering distribution channel - Patreon — Patreon
Vulnerable versions: abused as malicious archive hosting
Remediation for LummaStealer (V34XV4) Distributed via Fake Game-Update
Immediate actions
- Block and alert on the published SHA256 hashes (Updated Version.zip, game.exe, mains.js, modules.node, LummaStealer payload) across EDR and email/web gateways
- Treat any 'Updated Version.zip' or game.exe downloaded from a Patreon URL referenced in an itch.io comment as malicious; do not execute
- Hunt for a native DLL named modules.node written to %temp% and for processes loading it via Node-API
- Alert on game/Node.js-named executables spawning tasklist and wmic videocontroller/diskdrive enumeration in quick succession
Workarounds
- Disable execution of binaries from user Downloads/temp directories where feasible
- Use browsers/password managers that bind cookies and credentials to the device to reduce reuse of stolen tokens
Longer-term hardening
- Deploy EDR with behavioral detection for reflective/Node-API code loading and sandbox-evasion command bursts
- Educate game developers and players that itch.io comments and Patreon are not official update-delivery channels
- Restrict execution of unsigned single-file Node.js/nexe-packed binaries via application control (WDAC/AppLocker)
- Enforce phishing-resistant MFA and short session lifetimes to blunt cookie/session theft by infostealers
Timeline of LummaStealer (V34XV4) Distributed via Fake Game-Update
- LummaStealer (LummaC2) first advertised for sale on underground forums as a malware-as-a-service infostealer (since at least mid-2022).
- Microsoft begins a measurement window in which it identifies over 394,000 Windows computers globally infected by Lumma malware (through 2025-05-16).
- Microsoft DCU and the US DOJ disrupt LummaC2, seizing/blocking ~2,300 malicious C2 domains and the central command infrastructure and marketplaces.
- After June 2025 Lumma operators diversify hosting away from the prior Cloudflare-resolving pattern across multiple providers, and infection volumes rebuild toward pre-takedown levels.
- G DATA (Josemaria Grana) publishes analysis of the itch.io/Patreon fake-game-update campaign delivering LummaStealer variant V34XV4 via nexe-compiled loaders, with SHA256 IOCs and detections.
- Security press (Cyberpress, GBHackers, Hackread) report on the itch.io/Patreon Lumma distribution campaign and its reflective Node-API loading technique.
- LummaStealer infections surge as the operation increasingly leans on the CastleLoader loader and ClickFix social-engineering delivery (Dec 2025-Jan 2026).
- Threadlinqs documents TL-2026-0773 with full IOC set, MITRE mapping, and detection guidance for the itch.io/Patreon LummaStealer campaign.
Sources cited for LummaStealer (V34XV4) Distributed via Fake Game-Update
- Lumma Stealer: Danger lurking in fake game updates from itch.io and Patreon
- LummaStealer dropped via fake updates from itch.io and Patreon (G DATA)
- Cybercriminals Hijack Trust in Itch.io and Patreon with Bogus Game Updates Delivering Lumma Stealer
- Cybercriminals Use Fake Game Updates on Itch.io and Patreon to Push Lumma Stealer
- Lumma Stealer: Breaking down the delivery techniques and capabilities of a prolific infostealer
- Microsoft leads global action against favored cybercrime tool (Lumma Stealer disruption)
- Justice Department Seizes Domains Behind Major Information-Stealing Malware Operation
- Lumma Stealer (Malware Family) - Malpedia
- LummaC2 | Red Canary Threat Detection Report
- LummaStealer infections surge after CastleLoader malware campaigns (BleepingComputer)
Detection coverage for TL-2026-0773
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0773 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.