#Doenerium
Nearly 1 million PCs infected by malvertising on pirated streaming sites. Attackers used GitHub, Dropbox, & Discord to host info-stealers (Lumma, Doenerium) and NetSupport RAT. Microsoft removed the malicious GitHub repos.#MalvertisingStreamingThreat
March 6, 2025 at 9:04 PM
🎮 We analyzed an ongoing campaign targeting online gamers. Multiple malware families are delivered through fake video game websites such as #Epsilon, #Doenerium, #BByStealer, and #NovaSentinel.

blog.sekoia.io/game-over-ga...

#CTI #infostealer
Game Over: gaming community at risk with information stealers
This report was originally published for our customers on 26 October 2023. The world of online gaming, a thriving global community of millions, has become an enticing target for malicious actors seeki...
blog.sekoia.io
November 13, 2023 at 10:02 AM
Large-scale malvertising campaign from pirate streaming sites redirected to GitHub-hosted info stealers, compromising ~1M devices globally via multi-stage attack chain deploying Lumma, Doenerium, and NetSupport RAT.

www.microsoft.com/en...
Malvertising campaign leads to info stealers hosted on GitHub | Microsoft Security Blog
Microsoft detected a large-scale malvertising campaign in early December 2024 that impacted nearly one million devices globally. The attack originated from illegal streaming websites embedded with malvertising redirectors and ultimately redirected users to GitHub to deliver initial access payloads as the start of a modular and multi-stage attack chain.
www.microsoft.com
March 7, 2025 at 6:14 PM