Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo[.]org, 36-domain cluster) — Threadlinqs Intelligence
As of 2026-07-18, Latrodectus Phishing Campaign Delivering LummaStealer via 302-Redirect Domain Infrastructure (lufyfeo[.]org, 36-domain cluster) is a high-severity malware threat attributed to TA578 - G1038, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 45 indicators of compromise.
Threat ID: TL-2026-1483 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: TA578 - G1038 · FINANCIAL
Passive DNS analysis (Validin) of the phishing domain lufyfeo[.]org, resolving to 193.106.174.218, uncovered a 36-domain cluster sharing hosting infrastructure and an identical HTTP 302-redirect
Embee Research analyzed passive DNS records via Validin for the phishing domain lufyfeo[.]org, which resolves to 193.106.174.218. By pivoting on shared IP infrastructure and a distinctive HTTP 302-redirect fingerprint that sends victims onward to legitimate document-hosting domains (documentcloud.org and, historically, harvardlawreview.org), analysts identified a cluster of 36 related malicious domains reusing the same hosting and redirect pattern. This redirect-to-legitimate-domain technique is a defense-evasion tactic: automated URL scanners and email security gateways see the final-hop destination as a trusted, high-reputation site, masking the malicious first hop.
The infrastructure is assessed to support the Latrodectus malware loader ecosystem. Latrodectus (MITRE ATT&CK Software S1160) is a Windows downloader first observed in September-November 2023 and assessed by Proofpoint and Unit 42 researchers as a likely successor to IcedID, built by the same developer group. It has been distributed primarily by TA577 (a historically prolific Qbot/IcedID distributor) and TA578 (assessed as an initial access broker using fraudulent contact-form submissions and copyright-infringement lures). Per Unit 42 reporting from March 7-8, 2024, the observed infection chain is: thread-hijacked email > malicious link > redirect to a fake Microsoft Azure page > Firebase-hosted URL > oversized JavaScript file download > victim double-click > wscript.exe executes the JS > JS generates WebDAV traffic to fetch an MSI package > msiexec.exe installs the Latrodectus DLL (exported function "fin") > Latrodectus establishes C2 over HTTP(S) > operators push a Lumma Stealer executable over the Latrodectus C2 channel for final-stage credential/data theft.
Latrodectus performs environment/anti-sandbox checks (minimum running-process count, 64-bit architecture verification, valid MAC address validation) before executing, uses a mutex ("runnung") to prevent re-infection, and persists via AutoRun registry keys and Windows Scheduled Tasks, self-copying to an AppData path derived from its bot ID. Its C2 protocol issues HTTP POST requests with RC4-encrypted (hardcoded key "12345"), Base64-encoded payloads, and uses FNV-1a hashing for campaign-ID values. Documented command handlers include arbitrary code execution (cmd_exec_exe/dll/cmd), system/process/desktop enumeration (cmd_get_sysinfo/proclist/desktop), self-update (cmd_update), and a legacy IcedID-component downloader (cmd_run_icedid, handler #18) retained from Latrodectus's shared IcedID lineage. Latrodectus has also been used to deliver QakBot, DarkGate, and PikaBot in other campaigns, in addition to Lumma Stealer.
Lumma Stealer (LummaC2) is a widely distributed, subscription-based information stealer written in C++/ASM, hardened with LLVM-based control-flow flattening/obfuscation, dead-code injection, and low-level syscall usage ("Heaven's Gate") to evade EDR hooking, and known to inject into legitimate processes (msbuild.exe, regasm.exe, regsvcs.exe, explorer.exe). It harvests browser-stored credentials, session cookies and autofill data from Chromium- and Gecko-based browsers, cryptocurrency wallet files/extensions (MetaMask, Electrum, Exodus), VPN configuration files, FTP and email client credentials, Telegram data, and documents (PDF/DOCX/RTF) from user profiles, then exfiltrates them over a tiered C2 architecture — hardcoded Tier-1 C2 domains fronted by Cloudflare, with Steam-profile and Telegram-channel fallback pointers and, in newer builds, blockchain-based (EtherHiding-style) C2 retrieval. Traffic to hardcoded C2s uses ChaCha20 encryption; fallback URL retrieval uses a custom stack-based cipher and ROT+11 obfuscation. Microsoft's Digital Crimes Unit conducted a large-scale takedown of roughly 2,300 Lumma-associated domains in May 2025, though the malware-as-a-service operation has continued to rebuild infrastructure since.
The reuse of a fixed 302-redirect fingerprint across 36 domains sharing
Target sectors: all sectors opportunistic phishing, legal, professional services, finance, technology
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 45 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1566.002, T1204.001, T1059, T1047, T1569.002, T1547.001, T1053.005, T1053.005, T1218.007