# LummaStealer (V34XV4) Distributed via Fake Game-Update Comments on itch.io Linking to Patreon-Hosted nexe Loaders

> A single threat actor distributes the LummaStealer (LummaC2) infostealer by spamming fake game-update comments on legitimate itch.io games that link to a malicious 'Updated Version.zip' hosted on Patreon. The archive's game.exe is a nexe-compiled Node.js PE that runs obfuscated JavaScript (mains.js) to reflectively load a native DLL (modules.node) via the N-API export 'PodstilkaBidena', executing a Base64-encoded LummaStealer payload behind six layers of VM/sandbox-evasion checks.

- **Published:** 2026-06-10T00:00:00Z
- **Last reviewed:** 2026-06-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0773
- **ID:** TL-2026-0773
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

G DATA (Josemaria Grana) documented an active, ongoing malware campaign abusing the trust ecosystem of the indie-game platform itch.io and the creator-funding platform Patreon to distribute the LummaStealer (LummaC2) information stealer. The operator registers numerous freshly-created itch.io accounts and posts templated spam comments on the comment sections of legitimate games, impersonating official updates and directing victims to a Patreon URL that downloads an archive named 'Updated Version.zip'. Most files in the archive are benign decoys; the malicious component is 'game.exe', a 78.21 MiB Node.js application compiled to a Windows PE using the nexe packer.

On execution, game.exe runs obfuscated JavaScript (recovered as mains.js). The script first applies an aggressive six-level anti-analysis/sandbox-evasion gate: (1) terminate if system memory is under 4 GB or CPU cores are 2 or fewer; (2) compare os.userInfo() against a blacklist of 53+ analyst/sandbox usernames such as 'sandbox', 'vmware', 'malware', 'virus', 'test user', 'george', and 'wdagutilityaccount'; (3) enumerate running processes via 'tasklist /fo csv' and bail if any of 80+ analysis tools (IDA, Wireshark, Frida, OllyDbg, x64dbg, Burp Suite, etc.) are present; (4) detect virtual GPUs via 'wmic path win32_VideoController get name /value' (matching 'vmware svga 3d', 'virtualbox graphics adapter', 'microsoft basic display adapter'); (5) terminate if the display refresh rate read via 'wmic path Win32_VideoController get CurrentRefreshRate /value' is below 29 Hz; (6) detect virtual disks via 'wmic diskdrive get model /value' (matching 'vbox', 'vmware', 'virtio', 'qemu hardiskk'). Newer samples substitute PowerShell CIM cmdlets (Get-CimInstance Win32_VideoController) as fallback evasion methods, and all child commands are spawned hidden with 'windowsHide: true'.

If the environment passes the checks, a Base64-encoded LummaStealer payload is dropped to the %temp% directory as 'modules.node', a native DLL exporting napi_register_module_v1 and node_api_module_get_api_version_v1. Inside node_api_module_get_api_version_v1, the loader uses the Node-API functions napi_create_function and napi_set_named_property to register a C/C++ function named 'PodstilkaBidena' as a JavaScript property — a reflective code-loading technique that executes the LummaStealer payload inside the Node.js host process. LummaStealer then harvests browser credentials, cookies, autofill, cryptocurrency-wallet data, and other secrets, and can stage follow-on malware, exfiltrating over its C2 channel.

The campaign is attributed to a single actor on the strength of consistent tradecraft: continuous rotation of newly-created itch.io accounts that survive platform removals, distinct Patreon URLs per account that yield different encoded JavaScript variants, and per-sample mutation of variable/function names and encoding methods to delay signature detection. LummaStealer is a long-running malware-as-a-service offering (sold on underground forums since mid-2022, subscriptions from ~$250/month up to a ~$20,000 source-code option) that survived a major May 2025 Microsoft/DOJ takedown of ~2,300 C2 domains and has since rebuilt to pre-takedown infection levels, increasingly delivered via loaders such as CastleLoader and ClickFix social engineering. This itch.io/Patreon vector is a fresh distribution TTP for the family.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1608 Stage Capabilities
- T1583 Acquire Infrastructure
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1620 Reflective Code Loading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1564 Hide Artifacts
- T1497 Virtualization/Sandbox Evasion
- T1057 Process Discovery
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1518 Software Discovery
- T1555 Credentials from Password Stores
- T1539 Steal Web Session Cookie
- T1552 Unsecured Credentials
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1132 Data Encoding
- T1041 Exfiltration Over C2 Channel

## Sources

- [Lumma Stealer: Danger lurking in fake game updates from itch.io and Patreon](https://blog.gdatasoftware.com/2025/12/38310-lumma-stealer-itchio-patreon)
- [LummaStealer dropped via fake updates from itch.io and Patreon (G DATA)](https://www.gdatasoftware.com/blog/2025/12/38310-lumma-stealer-itchio-patreon)
- [Cybercriminals Hijack Trust in Itch.io and Patreon with Bogus Game Updates Delivering Lumma Stealer](https://cyberpress.org/lumma-stealer-malware/)
- [Cybercriminals Use Fake Game Updates on Itch.io and Patreon to Push Lumma Stealer](https://gbhackers.com/fake-game-updates/)
- [Lumma Stealer: Breaking down the delivery techniques and capabilities of a prolific infostealer](https://www.microsoft.com/en-us/security/blog/2025/05/21/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer/)
- [Microsoft leads global action against favored cybercrime tool (Lumma Stealer disruption)](https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/)
- [Justice Department Seizes Domains Behind Major Information-Stealing Malware Operation](https://www.justice.gov/opa/pr/justice-department-seizes-domains-behind-major-information-stealing-malware-operation)
- [Lumma Stealer (Malware Family) - Malpedia](https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma)
- [LummaC2 | Red Canary Threat Detection Report](https://redcanary.com/threat-detection-report/threats/lummac2/)
- [LummaStealer infections surge after CastleLoader malware campaigns (BleepingComputer)](https://www.bleepingcomputer.com/news/security/lummastealer-infections-surge-after-castleloader-malware-campaigns/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0773
