<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Lumma Stealer</title><description>Cybersecurity articles tagged #Lumma Stealer on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>ClickFix Social Engineering: How to Detect Fake Browser Update Attacks</title><link>https://runtimerebel.com/blog/clickfix-social-engineering-how-to-detect-fake-browser-update-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-social-engineering-how-to-detect-fake-browser-update-attacks</guid><description>ClickFix has become the dominant malware delivery method. Learn how attackers use fake browser error overlays to trick users into executing malicious PowerShell.</description><pubDate>Thu, 02 Jul 2026 07:39:48 GMT</pubDate><category>ClickFix</category><category>Social Engineering</category><category>Lumma Stealer</category><category>Initial Access</category><category>ClearFake</category></item><item><title>Lumma Stealer Distributed via Fake EditPro AI Image Generator</title><link>https://runtimerebel.com/blog/lumma-stealer-distributed-via-fake-editpro-ai-image-generator</link><guid isPermaLink="true">https://runtimerebel.com/blog/lumma-stealer-distributed-via-fake-editpro-ai-image-generator</guid><description>Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.</description><pubDate>Sat, 13 Jun 2026 09:17:02 GMT</pubDate><category>Lumma Stealer</category><category>EditPro AI</category><category>Infostealer</category><category>macOS Malware</category><category>Social Engineering</category></item><item><title>DriveSurge Campaigns: Detecting ClickFix and FakeUpdate Overlays</title><link>https://runtimerebel.com/blog/drivesurge-campaigns-detecting-clickfix-and-fakeupdate-overlays</link><guid isPermaLink="true">https://runtimerebel.com/blog/drivesurge-campaigns-detecting-clickfix-and-fakeupdate-overlays</guid><description>DriveSurge threat actors have hijacked thousands of sites to deploy ClickFix and FakeUpdate overlays, delivering info-stealers via deceptive browser alerts.</description><pubDate>Tue, 02 Jun 2026 01:03:09 GMT</pubDate><category>DriveSurge</category><category>ClickFix</category><category>Fake Updates</category><category>SocGholish</category><category>WordPress Security</category><category>Lumma Stealer</category><category>AsyncRAT</category></item><item><title>Hugging Face and ClawHub Abused for Malware Distribution</title><link>https://runtimerebel.com/blog/hugging-face-and-clawhub-abused-for-malware-distribution</link><guid isPermaLink="true">https://runtimerebel.com/blog/hugging-face-and-clawhub-abused-for-malware-distribution</guid><description>Threat actors are exploiting the trust of AI and code-hosting platforms like Hugging Face and ClawHub to distribute malware via social engineering lures.</description><pubDate>Fri, 01 May 2026 08:46:06 GMT</pubDate><category>Hugging Face</category><category>ClawHub</category><category>Lumma Stealer</category><category>Information Stealers</category><category>Social Engineering</category></item><item><title>Lumma Stealer and Sectop RAT Dual Infection Chain Analysis</title><link>https://runtimerebel.com/blog/lumma-stealer-and-sectop-rat-dual-infection-chain-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/lumma-stealer-and-sectop-rat-dual-infection-chain-analysis</guid><description>Technical breakdown of the Lumma Stealer and Sectop RAT (ArechClient2) infection chain, detailing C2 communication and persistence mechanisms.</description><pubDate>Fri, 17 Apr 2026 08:45:30 GMT</pubDate><category>Lumma Stealer</category><category>Sectop RAT</category><category>Arechclient2</category><category>Infostealer</category><category>Threat Intelligence</category></item><item><title>Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys</title><link>https://runtimerebel.com/blog/lumma-stealer-phishing-campaign-avoiding-copyright-notice-decoys</link><guid isPermaLink="true">https://runtimerebel.com/blog/lumma-stealer-phishing-campaign-avoiding-copyright-notice-decoys</guid><description>Phishing campaign targets healthcare and government sectors with copyright infringement decoys to deliver Lumma Stealer via legitimate cloud services.</description><pubDate>Mon, 23 Mar 2026 16:27:17 GMT</pubDate><category>Lumma Stealer</category><category>Meduza Stealer</category><category>Phishing</category><category>Infostealer</category><category>Social Engineering</category></item><item><title>InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers</title><link>https://runtimerebel.com/blog/installfix-campaign-cloned-ai-tool-sites-distribute-info-stealers</link><guid isPermaLink="true">https://runtimerebel.com/blog/installfix-campaign-cloned-ai-tool-sites-distribute-info-stealers</guid><description>The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.</description><pubDate>Mon, 09 Mar 2026 12:19:23 GMT</pubDate><category>InstallFix</category><category>AI Tools</category><category>Lumma Stealer</category><category>PowerShell</category><category>Infostealer</category></item><item><title>Windows Terminal Exploited in ClickFix Campaign for Lumma Stealer</title><link>https://runtimerebel.com/blog/windows-terminal-exploited-in-clickfix-campaign-for-lumma-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-terminal-exploited-in-clickfix-campaign-for-lumma-stealer</guid><description>Microsoft identifies a new ClickFix campaign using Windows Terminal to deliver Lumma Stealer. Analysis of social engineering TTPs and mitigation steps included.</description><pubDate>Fri, 06 Mar 2026 08:14:22 GMT</pubDate><category>ClickFix</category><category>Lumma Stealer</category><category>Windows Terminal</category><category>Social Engineering</category><category>Microsoft</category></item></channel></rss>