A sophisticated, ongoing malware campaign involving Lumma Stealer is exploiting compromised educational institutions to distribute malicious PDF-themed LNK files. These files trigger a multi-stage infection, stealing credentials, browser data, and cryptocurrency information. Targeting industries like finance and healthcare, the attackers use Steam profiles for command-and-control operations, evading detection. This campaign highlights the increasing risks of phishing and social engineering tactics, urging organizations to enhance cybersecurity through awareness training, endpoint protection, and network monitoring.
