Gavnosource.rar -
The file is a widely discussed malware sample within the cybersecurity community, primarily recognized as a variant of the Lumma Stealer (an Information Stealer) distributed through social engineering campaigns targeting developers and gamers. Executive Summary Malware Type: InfoStealer (Lumma variant)
Scans for browser extensions and desktop files related to MetaMask, Binance, Phantom, and Atomic Wallet. gavnosource.rar
Steals saved passwords, credit card info, and autofill data from Chrome, Edge, and Firefox. The file is a widely discussed malware sample
Outbound traffic to unusual TLDs (like .pw , .icu , or .top ) which are frequently used by Lumma Stealer C2 panels. and Atomic Wallet. Steals saved passwords