{"id":215473,"date":"2026-02-15T11:30:00","date_gmt":"2026-02-15T16:30:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/02\/15\/lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups\/"},"modified":"2026-02-19T19:55:11","modified_gmt":"2026-02-20T00:55:11","slug":"lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/02\/15\/lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups\/","title":{"rendered":"Lumma Stealer and Ninja Browser malware campaign abusing Google Groups"},"content":{"rendered":"<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups\/\">Lumma Stealer and Ninja Browser malware campaign abusing Google Groups<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-02-15 11:30:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.bleepingcomputer.com\">www.bleepingcomputer.com<\/a><\/p>\n<p style=\"text-align:center\">\n<p>CTM360 reports that more than 4,000 malicious Google Groups and 3,500 Google-hosted URLs are being used in an active malware campaign targeting global organizations.<\/p>\n<p>The attackers abuse Google\u2019s trusted ecosystem to distribute credential-stealing malware and establish persistent access on compromised devices.<\/p>\n<p>The activity is global, with attackers embedding organization names and industry-relevant keywords into posts to increase credibility and drive downloads.<\/p>\n<p>Read the full report here: https:\/\/www.ctm360.com\/reports\/ninja-browser-lumma-infostealer<\/p>\n<h2>How the campaign works<\/h2>\n<p>The attack chain begins with social engineering inside Google Groups. Threat actors infiltrate industry-related forums and post technical discussions that appear legitimate, covering topics such as network issues, authentication errors, or software configurations<\/p>\n<p>Within these threads, attackers embed download links disguised as: \u201cDownload {Organization_Name} for Windows 10\u201d<\/p>\n<p>To evade detection, they use URL shorteners or Google-hosted redirectors via Docs and Drive. The redirector is designed to detect the victim\u2019s operating system and deliver different payloads depending on whether the target is using Windows or Linux<br \/>\n\u00a0<\/p>\n<p style=\"text-align:center\"><img decoding=\"async\" alt=\"Malware lifecycle\" height=\"600\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/security\/c\/ctm360\/lummastealer-ninjabrowser\/ctl360-malware-lifecycle.jpg\" width=\"445\"\/><\/p>\n<h2>Windows Infection Flow: Lumma Info-Stealer<\/h2>\n<p>For Windows users, the campaign delivers a password-protected compressed archive hosted on a malicious file-sharing infrastructure<\/p>\n<h3>Oversized archive to evade detection<\/h3>\n<p>The decompressed archive size is approximately 950MB, though the actual malicious payload is only around 33MB. CTM360 researchers found that the executable was padded with null bytes \u2014 a technique designed to exceed antivirus file-size scanning thresholds and disrupt static analysis engines.<\/p>\n<h3>AutoIt-based reconstruction<\/h3>\n<p>Once executed, the malware:<\/p>\n<ul style=\"list-style-type:square\">\n<li aria-level=\"1\">\n<p role=\"presentation\">Reassembles segmented binary files.<\/p>\n<\/li>\n<li aria-level=\"1\">\n<p role=\"presentation\">Launches an AutoIt-compiled executable.<\/p>\n<\/li>\n<li aria-level=\"1\">\n<p role=\"presentation\">Decrypts and executes a memory-resident payload.<\/p>\n<\/li>\n<\/ul>\n<p>The behavior matches Lumma Stealer, a&#8230;<\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lumma Stealer and Ninja Browser malware campaign abusing Google Groups https:\/\/www.bleepingcomputer.com\/news\/security\/ctm360-lumma-stealer-and-ninja-browser-malware-campaign-abusing-google-groups\/ Publish Date: 2026-02-15 11:30:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":215474,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.bleepstatic.com\/content\/posts\/2026\/02\/12\/CTM360-REPORT-BANNER.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[36,32],"class_list":["post-215473","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-infostealer","tag-malware"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215473"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=215473"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215473\/revisions"}],"predecessor-version":[{"id":215475,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215473\/revisions\/215475"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/215474"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=215473"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=215473"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=215473"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}