meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Monday, April 20th, 2026: Lumma Stealer and Sectop RAT; Windows 0-Day Exploited; NIST NVD Update; FortiSandbox PoC

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 20 April 2026

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Monday, April 20th, 2026: Lumma Stealer and Sectop RAT; Windows 0-Day Exploited; NIST NVD Update; FortiSandbox PoC

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, April 20th,

0:07.6

2006 edition of the Sands Internet Storms Centers.

0:11.9

Stormcast, my name is Johannes Ulrich,

0:14.4

recording today from Amsterdam, Netherlands.

0:18.0

And this episode is brought you by the Sands.edu credit certificate program in cyber security fundamentals.

0:25.9

In the iris today, we got another reverse analysis and forensics walkthrough by a Pratt.

0:31.3

A Pratt is talking about Luma Steeler and Sacktop Rat.

0:36.2

The way this particular infection starts is sadly the common trick of offering commercial

0:42.1

software for free.

0:43.9

So basically the cracked version of various Adobe products in this particular case, the user

0:49.7

then downloads an actually suspiciously small SIP, that then extracts into a rather large,

0:57.0

like around 800 megabyte executable.

1:00.5

The executable is so large because it's just padded with zeros, and that, of course, is often

1:06.0

used to prevent anti-malware products from scanning it.

1:09.7

In this case, it may also make the particular

1:12.9

executable more plausible because the user may expect a certain size executable for these products.

1:21.1

Now, as the user then starts the executable, that's where Luma Steeler is first installed, and then later SETOPRAT.

1:30.3

So first credentials are being stolen, and then persistent access is being provided by the remote access tool.

1:39.3

And then we have a series of postings by Hunter's Labs 2X that explain how they're seeing the three recent

1:48.7

vulnerabilities in Windows Defender being exploited. All of these three vulnerabilities were

1:55.5

discovered and proof of concept code was released by an individual that goes by the name of Nightmare Eclipse.

2:03.1

The first vulnerability here is referred to as undefend. This vulnerability just disables a Windows

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.