Security researchers have discovered a new phishing campaign that exploits gamers' excitement for the start of the League of Legends (LoL) World Championship and spreads info-stealer malware .

Bitdefender researchers reported that they have detected malicious ads on social media promoting free downloads of League of Legends . By clicking on the ad, victims are taken to a download page for the game, which mimics the domain and general appearance of the legitimate version.
See also: Zimperium: Mobile devices targeted by phishing attacks
“Once the user clicks on the download link, they are directed to a Bitbucket repository containing a malicious file,” Bitdefender explained.
“The download file contains an executable file along with a legitimate Windows file, user32.dll. The executable acts as a dropper for Lumma Stealer, a dangerous infostealer malware known for its extensive ability to collect data from infected devices.“.
Lumma Stealer can steal passwords, card details, cryptocurrency wallets, browser session cookies, and more.
This information can be used for further attacks or sold to other cybercriminals.
Bitdefender warned that the infostealer malware can enter the system through malicious advertising for League of Legends and remain unnoticed.
See also: Phishing platform iServer taken down by authorities
The LoL World Championship kicked off yesterday, September 25th, and will run until November 2nd, with matches in London, Paris, and Berlin.
According to Bitdefender, the phishing campaign has targeted over 4000 people.
The company offers some protection tips:
- Check URLs before clicking links, especially if they are in social media ads
- Avoid downloading software from unofficial sources
- Be careful with online ads
- Use reliable anti-malware tools to block malicious files and phishing
See also: SambaSpy Malware: Targets Italian users with phishing emails
Extra tips
It's important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.
Source: www.infosecurity-magazine.com
