This malware uses trigonometry to stop it from being detected and blocked
The notion that hackers are constantly evolving their tactics has once again been proven, after a new strain of malware user was found to be using trigonometry to avoid detection.
Cybersecurity researchers Outpost24 recently analyzed the latest version of Lumma Stealer, a known infostealer malware capable of grabbing passwords stored in popular browsers, cookies, credit card information, and data related to cryptocurrency wallets. Lumma is offered as a service, for a subscription fee ranging between $250 and $1,000.
In its analysis, Outpost24’s researchers found that Lumma’s fourth version comes with a number of new evasion techniques, allowing it to operate next to most antivirus or endpoint protection services. These techniques include control flow flattening obfuscation, human-mouse activity detection, XOR encrypted strings, support for dynamic configuration files, and enforcement of crypto use on all builds.
Using mouse movement
Of these techniques, the detection of human-mouse activity is the most interesting one, as that’s how the infostealer can see if it’s running in an antivirus sandbox. As the researchers explain, the malware tracks the cursor’s position and records a series of five distinct positions in intervals of 50 milliseconds. Then, using trigonometry, it analyzes these positions as Euclidean vectors, calculating the angles and vector magnitudes that form the detected movement.
Vector angles below 45 degrees mean the mouse is being operated by a human. If the angles are higher, the infostealer assumes it’s being run in a sandbox and stops all activity. It resumes operations once it determines mouse activity as human again.
The threshold of 45 degrees is arbitrary, the researchers further stated, suggesting that it’s probably based on research data.
Infostealers are a popular hacking tool, as they allow threat actors to gain access to important services, such as social media accounts or email accounts. Furthermore, by stealing banking data or cryptocurrency wallet-related data, the attackers can steal victim funds and crypto tokens.
Via BleepingComputer
More from TechRadar Pro
The notion that hackers are constantly evolving their tactics has once again been proven, after a new strain of malware user was found to be using trigonometry to avoid detection. Cybersecurity researchers Outpost24 recently analyzed the latest version of Lumma Stealer, a known infostealer malware capable of grabbing passwords stored…
Recent Posts
- Nvidia unveils custom high-bandwidth memory promising higher bandwidth and lower power use – but who will actually get to use it?
- Flock cameras are officially banned on state roads in Florida
- The White House is making arcade games racist
- Google patches multiple browser bugs including one that was under active exploitation — so update now
- I tried these stylish, futuristic-looking open earbuds, and although they boast sound by Bose, they’re not as harsh on your wallet — here’s everything you need to know
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023