SANS Stormcast Thursday, January 15th, 2026: Luma Streal Repeat Infection; ServiceNow Broken Auth; Starlink/GPS Jamming
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 January 2026
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, January 15th, 2026 edition of the Sands Internet Storms |
| 0:11.1 | StormCast. My name is Johannes Ulrich, recording today from Jacksonville, Florida. And this episode is |
| 0:18.0 | brought to you by the Sands., credit certificate program in incident response. |
| 0:23.7 | In Diaries today, we got a malware write-up by Brad. |
| 0:27.8 | Brad is writing about a recent version of Luma Steeler. |
| 0:31.1 | Luma Steeler, as the name implies, is an info stealer. |
| 0:34.1 | Now, in this particular case, it will infiltfiltrate your data, and then it will download |
| 0:40.1 | an additional URL from Pastebin with instructions on what to do next. At this point, the odd new |
| 0:48.4 | behavior here of this variety of Luma Steeler is that it adds a scheduled task to keep repeatedly doing this. |
| 0:56.1 | But then whenever it downloads the next binary or whatever it's going to load on your system, |
| 1:03.5 | well, it adds another scheduled task. So these scheduled tasks keep piling up. Apparently, |
| 1:10.7 | they're scheduled every 30 minutes, |
| 1:12.6 | and Brad observed systems running up to 30 or so of these scheduled tasks, |
| 1:18.5 | meaning every minute at that point, |
| 1:20.9 | a new variety of malware is being downloaded and executed, |
| 1:24.5 | which of course should make the infection more noisy. But note that all of this |
| 1:29.5 | happens after the bulk of the data exfiltration already happened. So at this point, I think |
| 1:35.6 | the attacker is less worried about being discovered and probably is more attempting to scrape |
| 1:42.4 | any kind of additional information from the system that was |
| 1:46.2 | initially missed. It's also possible that they're then sort of handing on the system to some |
| 1:53.0 | other group that installs whatever Malver. They prefer ransomware or whatever. |
| 1:59.1 | And then we have yet another interesting, gentic AI vulnerability. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

