Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hackers use leaked shelter tool licenses to spread Lumma Stealer and Sectoprat malware

Anatsa Android Banking Trojan hits 90,000 users with fake PDF apps on Google Play

The latest update for Mastodon prepares quote posts, Revamps Design app

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Hackers use leaked shelter tool licenses to spread Lumma Stealer and Sectoprat malware
Identity

Hackers use leaked shelter tool licenses to spread Lumma Stealer and Sectoprat malware

userBy userJuly 8, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 8, 2025Ravi LakshmananMalware/Cybercrime

In yet another example of threat actors reusing legal tools for malicious purposes, hackers have been found using a popular red teaming tool called shelters to distribute steeler malware.

The company behind the software said that the company that recently purchased a Shellter Elite license leaked a copy, urging malicious actors to weaponize the tools of their Infostealer campaign. An update was then released to plug in the issue.

“We have found ourselves tackling this unfortunate situation despite the rigorous review process that has successfully prevented such incidents since the launch of Shellter Pro Plus in February 2023,” the Shellter Project team said in a statement.

Cybersecurity

This response comes shortly after the Elastic Security Lab released a report on how commercial avoidance frameworks have been abused in the wild to propagate Lumma Stealer, Rhadamanthys Stealer, and Sectoprat (aka Arechclient2) since April 2025.

Shellter is a powerful tool that allows offensive security teams to bypass antivirus and endpoint detection and response (EDR) software installed on endpoints.

Elastic said it had leveraged Shelter Elite Version 11.0 on April 16, 2025 to identify multiple financially motivated infosealer campaigns using shelter to package payloads since late April 2025.

“Shelt-protected samples generally use self-correcting shellcode with polymorphic obfuscation to incorporate themselves into legitimate programs,” the company said. “This combination of legitimate instructions and polymorphic code helps these files avoid static detection and signatures, leaving them undetectable.”

Some of the campaigns offering theft of Sectoprat and Rhadamanthys are believed to have adopted the tool after version 11 was sold in the popular cybercrime forum in mid-May, using a YouTube video that offers game modes like game modes like Fortnite Mod, using lures related to sponsorship opportunities targeting content creators.

Meanwhile, the Lumma Stealer attack chain is said to have become popular via payloads hosted on MediaFire in late April 2025.

Cybersecurity

It’s not surprising that Shellter follows a similar trajectory, as cracked versions of Cobalt Strike and Brute Ratel C4 have previously found ways to go to the hands of cybercriminals and nation-state actors.

“Despite the best efforts of the commercial OST community to retain tools for legitimate purposes, mitigation methods are incomplete,” Elastic said. “While shelter projects are victims of this case through intellectual property loss and future development times, other participants in the security space must contest the actual threats wielding more competent tools.”

However, the shelter project criticized its resilience for “prioritizing publicity for public safety” and for acting in a way that was said to be “reckless and professional” by notifying it quickly.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAnatsa Android Banking Trojan hits 90,000 users with fake PDF apps on Google Play
user
  • Website

Related Posts

Anatsa Android Banking Trojan hits 90,000 users with fake PDF apps on Google Play

July 8, 2025

Malicious Pull Request Targets Over 6,000 Developers Target via Vulnerable Escode vs Code Extensions

July 8, 2025

Five ways identity-based attacks are violating retail

July 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hackers use leaked shelter tool licenses to spread Lumma Stealer and Sectoprat malware

Anatsa Android Banking Trojan hits 90,000 users with fake PDF apps on Google Play

The latest update for Mastodon prepares quote posts, Revamps Design app

Moonvalley’s “ethical” AI video model for filmmakers has been released

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Robots Play Football in Beijing: A Glimpse into China’s Ambitious AI Future

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.