[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpfQHzM0UYXwmpngvz54ahHUx7RxbD83Xa8yE2HV6Rb8":3},{"article":4,"iocs":46,"watch_terms":60},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":30},"7a49f43d-2dce-48be-baf6-4b7ed2be2826","#SEOPoisoning seen delivering #LummaStealer via fake YubiKey pages. The attack chain utilizes DLL...","seopoisoning-seen-delivering-lummastealer-via-fake-yubikey-pages-the-attack-chai-e84026","#SEOPoisoning seen delivering #LummaStealer via fake YubiKey pages. The attack chain utilizes DLL sideloading and PowerShell-based defense evasion to deploy a heavily obfuscated AutoIt loader, which ultimately injects Lumma Stealer directly into memory: https:\u002F\u002Ft.co\u002Fr0UuZvh802 https:\u002F\u002Ft.co\u002FxqwMeMoClU","Attackers are using SEO poisoning to rank malicious pages impersonating YubiKey, distributing LummaStealer infostealer malware. The attack chain employs DLL sideloading, PowerShell defense evasion, and an obfuscated AutoIt loader to inject the stealer directly into memory. This targets users searching for legitimate hardware security keys and credential management.","SEO poisoning campaign distributes LummaStealer via counterfeit YubiKey pages.",null,"https:\u002F\u002Fx.com\u002FUnit42_Intel\u002Fstatus\u002F2046703360527483145","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHGdZyR4XgAAWiXU.jpg","2026-04-21T21:31:21+00:00","2026-04-21T22:00:07.676593+00:00",8,[18,21,24],{"name":19,"type":20},"YubiKey","product",{"name":22,"type":23},"AutoIt","technology",{"name":25,"type":23},"PowerShell","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":26,"icon":11,"name":28,"slug":29},"Malware","malware",[31,36,41],{"category":32},{"id":33,"icon":11,"name":34,"slug":35},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":37},{"id":38,"icon":11,"name":39,"slug":40},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":42},{"id":43,"icon":11,"name":44,"slug":45},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[47,50,54,57],{"type":29,"value":48,"context":49},"LummaStealer","Information stealer malware injected into memory via obfuscated AutoIt loader",{"type":51,"value":52,"context":53},"mitre_attack","T1574.002","DLL sideloading technique used in attack chain",{"type":51,"value":55,"context":56},"T1059.001","PowerShell-based defense evasion",{"type":51,"value":58,"context":59},"T1055","Process injection of LummaStealer into memory",[19]]