Hackers are targeting other hackers with a fake OnlyFans tool that claims to help steal accounts, but instead infects malicious actors with the infostealer Lumma.
See also: North Korean hackers use fake FreeConference app to scam users

The operation, discovered by Veriti Research, is a prime example of the blurred lines between being predator or prey in the world of cybercrime ,where twists and backstabbing are abound.
OnlyFans is a hugely popular subscription-based adult content platform where creators can earn money from users (referred to as “fans”) who pay to access their content. Creators can share videos, images, messages, and live streams with their subscribers, while subscribers pay a recurring fee or one-time payments for exclusive content.
Given its popularity, OnlyFans accounts are often targets of hackers who try to steal them to obtain fans' payments, extort the account owner to pay a ransom, or simply leak private photos.
The verification tools are designed to help validate large sets of stolen login credentials (usernames and passwords), checking whether the login details match any OnlyFans account and whether they are still valid.
Without these tools, cybercriminals would have to manually try thousands of credential pairs, an impractical and tedious process that wouldmake the system unviable. However, these tools for OnlyFans are usually created by other cybercriminals, leading hackers to trust that they are safe to use, which in some cases is not the case.
See also: Earth Lusca hackers use the new KTLVdoor backdoor
Veriti discovered a case of an OnlyFans controller that promises to verify credentials, check account balances, verify payment methods, and determine creator rights, but instead installs the malicious Lumma software that steals information.

The payload, called “brtjgjsefd.exe”, is taken from a GitHub and uploaded to the computer .
Lumma is a malware-as-a-service (MaaS) that steals information that has been rented to cybercriminals since 2022 for $250-1000 per month and is distributed in various ways, such as malicious advertising, YouTube comments, torrents and more recently, GitHub comments.
It is an advanced information theft system with innovative evasion mechanisms and the ability to restore expired Google session tokens . It is primarily known for stealing two-factor authentication codes, cryptocurrency wallets, and passwords, cookies, and credit cards stored in the victim’s browser and file system. Lumma also acts as a loader, capable of injecting additional payloads into the compromised system and executing PowerShell scripts . And now it’s affecting hackers targeting OnlyFans too!
Veriti found that when the Lumma Stealer payload is released, it will connect to a GitHub account named “UserBesty,” which the cybercriminal behind this campaign uses to host other malicious payloads.
See also: Verkada: Fine – Hackers had access to customer security cameras
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Infostealer is a type of malware designed to infiltrate a user's system and extract sensitive information without the user's knowledge. This can include personal data such as usernames, passwords, credit card details, and other confidential information. Often, infostealers are distributed via phishing emails, malicious downloads, or compromised websites. Once installed, these programs can operate silently, sending the data back to the attacker. The impact of Infostealer infections can be severe, leading to identity theft, financial loss, and significant breaches of personal security. To protect yourself from such threats, it is essential to use reputable antivirus software, practice safe browsing habits , and remain vigilant about the links and attachments you interact with online.
Source: bleepingcomputer
