Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Water Kurita

Also known as: Storm-2477, tracked as

Description

Water Kurita is a financially driven cybercriminal collective that has been linked to the Lumma “Stealer” infostealer‑as‑a‑service (MaaS) ecosystem. The group rose to prominence after law‑enforcement takedowns of its central marketplace and command infrastructure, which exposed core members in a 2025 doxxing operation. Following these disruptions, Water Kurita quickly reestablished operations by deploying new C2 servers behind Cloudflare and expanding delivery via alternative channels. The actor’s delivery tactics pivot around GitHub-based fake or compromised repositories (the FakeGit campaign), as well as malvertising, search‑engine manipulation, and social‑media promotions on platforms such as YouTube and Facebook. These vectors funnel victims to an installer that leverages MicrosoftEdgeUpdate.exe for process injection into Chrome processes, enabling stealthy persistence and data gathering. On the technical side, Water Kurita relies heavily on browser fingerprinting and system profiling to evade sandbox detection. The malware performs dynamic exploitation of the IDRAC remote‑management firmware to wipe disks if remediation fails, and can employ a secondary payload (GhostSocks) for environment detection or lateral movement. Data exfiltration occurs over standard HTTP/HTTPS to C2 endpoints such as “/api/set_agent” on domains like jamelik.asia, using query‑parameterized GET requests that include user IDs and tokens. Operationally, Water Kurita sustains revenues by monetizing data in two phases: a subscription model that delivers freshly stolen credentials to customers, and an aftermarket resale of high‑value databases. Its persistence mechanisms enable rapid redeployment after takedowns, ensuring continued income streams despite counter‑measures.

Goals & Targeting

Targeted Sectors

Media
Financial services
Pharmaceutical
Critical infrastructure
Aviation
Government
Defense

Targeted Countries / Regions

CN
IR
IL
JP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Water Kurita is a financially motivated cybercriminal group that operates the Lumma Stealer MaaS platform, using stealthy browser deliveries and process injection to exfiltrate credentials on a mass‑scale. The group’s recent 2025 doxxing campaign exposed its core members and temporarily disrupted its infrastructure, but activity resumed quickly through new C2 channels and diversified delivery vectors. It primarily monetizes stolen data by reselling credentials via subscription services, targeting a wide array of sectors across China, Iran, Israel, and Japan.

Goals & Targeting

Water Kurita’s primary objective is financial gain through large‑scale credential theft and data monetization. The group specifically targets sectors that handle sensitive or highly profitable information, including media, financial services, pharmaceuticals, critical infrastructure, aviation, government, and defense. The actor focuses on threat landscapes in China, Iran, Israel, and Japan, exploiting localized supply chains and leveraging local regulatory gaps to maximize the value of stolen data.

Enhanced Description

Key Capabilities

  • Doxxing and information exfiltration via Lumma Stealer
  • Browser fingerprinting for detection evasion and sandbox avoidance
  • Stealthy installation and persistence mechanisms
  • GitHub-based delivery through FakeGit campaign
  • Process injection from MicrosoftEdgeUpdate.exe into Chrome processes
  • Selective payload deployment based on victim environment
  • Data exfiltration over HTTP to C&C endpoints
  • Use of GhostSocks secondary payload for detection or movement
  • Exploitation of IDRAC remote‑management controller vulnerability for disk wiping
  • Phishing sites masquerading as control panels for data harvesting
  • Cloudflare CDN usage to mask true C&C origins
  • Malvertising, search engine manipulation, and JavaScript redirection to drive downloads
  • Creation of fake GitHub repositories with AI‑generated README files
  • Leverage social media platforms for bulk malware distribution

MITRE ATT&CK Tactics

Execution
Defense Evasion
Discovery
Command and Control
Exfiltration
Initial Access
Credential Collection

ATT&CK Techniques

T1053.006
T1041
T1055
T1078
T1078.004
T1071
T1071.001
T1082
T1036
T1064
T1133
T1190
T1195
T1528
T1566.002
T1571
T1620

Software / Tooling

Lumma Stealer
FakeGit
GhostSocks
Derusbi
PlugX
Duqu
Winnti
Amadey
Messagetap
Disco
Empire

Campaigns & Victims

Water Kurita operates at an opportune tempo, rapidly rebuilding its infrastructure after each takedown. Known campaigns include the high‑volume FakeGit GitHub repo abuse and a 2025 doxxing incident that forced operational pivots. Victim profiles span mid‑market organizations in finance, media, pharmaceuticals, critical infrastructure, aviation, government, and defense across China, Iran, Israel, and Japan. The actor’s modus operandi blends multiple delivery vectors—malvertising, social‑media, GitHub, and phishing—to maximize reach, while its use of cloud proxies and CDN masking enables resilient command & control despite defensive countermeasures.

IOC Patterns

  • Domain name
  • Email address
  • File hash (SHA-256)
  • Endpoint path (/api/set_agent)
  • HTTP GET query parameters (uid, auth token)
  • IDRAC firmware vulnerability indicator
  • Phishing URL masquerade
  • Malvertising redirect pattern
  • JavaScript‑based redirection to secondary download sites
  • Cloudflare CDN obfuscation
  • GitHub repository README content

Recommended Actions

  • Block known Lumma Stealer C&C domains and IPs via threat intelligence feeds.
  • Monitor for process injection into browsers (e.g., chrome.exe) and alert on anomalous execution from MicrosoftEdgeUpdate.exe.
  • Apply endpoint behavioral analytics to detect VM/sandbox evasion indicators such as browser fingerprinting signatures.
  • Inspect outbound HTTP traffic for suspicious API endpoints like /api/set_agent and flagged query parameters.
  • Harden Dell IDRAC infrastructure: enforce firmware updates, restrict remote access protocols, and monitor for abnormal delete/wipe activity.
  • Block phishing sites that mimic legitimate control panels; integrate URL reputation checks in gateway firewalls.
  • Implement web filtering to block JavaScript redirect loops to TDS/secondary download sites and mitigate malvertising campaigns.
  • Flag or quarantine suspicious GitHub repositories containing AI‑generated README content or game cheat promotions.
  • Deploy robust ad‑blockers and safe browsing extensions on endpoints, and enable anti‑malvertising controls.
  • Maintain up‑to‑date antivirus signatures for Lumma Stealer variants and GhostSocks, and deploy host‑based intrusion detection systems.

Suggested Tags

Water Kurita
Lumma Stealer
FakeGit
Doxxing
Information-Stealing-as-a-Service
Process Injection
Browser Fingerprinting
GhostSocks
Command and Control Web
Virtualization Detection
Domain Sinkhole
Malware-as-a-Service
Phishing Site
Cloudflare Obfuscation
IDRAC Exploit
Social Media Distribution
Malvertising
Search Engine Manipulation

Confidence Assessment

The analysis is based on multiple publicly available reports, law‑enforcement takedown disclosures, and technical de‑composition of the Lumma Stealer malware. While there is high confidence in documented delivery methods, stealth techniques, and identified tools, gaps remain regarding the full organizational structure of Water Kurita, the exact operational tempo over time, and the detailed extent of its subscription/marketplace revenue model.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 8 Email Address 3 Domain 8 SHA-256 Hash 1

References

  1. mallory.ai — Cited by web research for: T1195
  2. www.trendmicro.com — Cited by web research for: ClickFix
  3. www.trendmicro.com — Cited by web research for: LummaStealer
  4. www.hexnode.com — Cited by web research for: malware distribution
  5. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  6. www.rescana.com — Cited by web research for: CVE-2025-61882
  7. https://www.fortra.com/blog/cybercriminals-turn-each-other-story-lumma-stealers-collapse — Cited by AI analysis.
  8. https://cyberalert.com.pl/articles/lumma-stealer-analiza-2025.html — Cited by AI analysis.
  9. https://www.linkedin.com/posts/cyber-news-live_fakegit-campaign-uses-7600 — Cited by AI analysis.
  10. https://www.rescana.com/post/active-exploitation-alert-fakegit-campaign-abuses-7-600-github-repositories — Cited by AI analysis.

Intel Summary

19

Techniques

46

Tools

0

Campaigns

23

IOCs

0

Observed Data

9

Tactics

Tags

Critical Infrastructure
Data Exfiltration
Water Kurita
Lumma Stealer
FakeGit
Doxxing
Information-Stealing-as-a-Service
Process Injection
Browser Fingerprinting
GhostSocks
Command and Control Web
Virtualization Detection
Domain Sinkhole
Malware-as-a-Service
Phishing Site
Cloudflare Obfuscation
IDRAC Exploit
Social Media Distribution
Malvertising
Search Engine Manipulation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.