Common signs include suspicious PowerShell usage, covert HTTP POST traffic, unusual API calls, and endpoint activity that does not leave the usual dropped-file artifacts. Teams should also look for browser credential access, screenshot capture, and exfiltration patterns tied to in-memory execution. The absence of a persistent file does not mean the host is clean.
What makes a LummaC2-style infection hard to spot?
The core issue is that the malware can operate largely inside legitimate processes and memory rather than relying on an obvious dropped executable. That shifts detection away from file-based indicators and toward behavioural evidence, such as scripting abuse, suspicious network traffic, and unusual access to browser data or screenshots.
When the payload is memory-resident, normal endpoint controls may see only partial activity, so defenders need to treat “no file found” as an inconclusive result, not a clean bill of health.
Which behaviours most strongly suggest in-memory execution?
Suspicious PowerShell usage is one of the clearest clues, especially when it is paired with obfuscation, child-process spawning, or command patterns that do not fit the host’s normal admin work. Covert HTTP POST traffic is another strong signal, particularly when the destination is unusual, the cadence is repetitive, or the content looks like staged exfiltration rather than routine application traffic.
Unusual API calls also matter because in-memory loaders and stealers often interact with Windows or browser APIs to read credentials, capture screens, or move data without creating a persistent artifact. Those calls become more suspicious when they appear in short bursts, originate from non-standard parent processes, or happen outside a normal user workflow.
What endpoint and data-access patterns should teams investigate?
Look for endpoint activity that does not leave the usual dropped-file trail, because memory-only execution often bypasses the artifacts that file-based detection expects. Browser credential access is particularly important, since token, password, and session theft can happen quickly and silently before the host shows any obvious persistence.
Screenshot capture and exfiltration patterns strengthen the case when they occur alongside scripting and network indicators, because they point to a collection phase rather than random process noise. For broader technique mapping, the MITRE ATT&CK Enterprise Matrix is the most useful reference for aligning observed behaviour with credential access, collection, and exfiltration patterns.
Risk and Threat Considerations
A LummaC2-like infection is risky because it can steal usable session material and user credentials before conventional endpoint controls register a durable malware footprint. The attacker does not need long persistence if the goal is rapid browser theft, credential harvesting, and short-lived exfiltration from memory.
Failure mechanism: The malware runs inside memory or legitimate processes, abuses scripting and API access, and blends network exfiltration into ordinary-looking HTTP activity.
Impact: Defenders may miss the compromise until accounts, sessions, or data have already been abused, rotated, or monetised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1059 — Command and Scripting Interpreter | PowerShell abuse is a primary sign of in-memory malware execution. |
| T1071.001 — Application Layer Protocol: Web Protocols | Covert HTTP POST traffic is a common command-and-control or exfiltration pattern. | |
| T1555 — Credentials from Password Stores | Browser credential access is a key indicator of credential theft activity. | |
| Recommendation — Map suspicious scripting to T1059 and hunt for encoded, obfuscated, or child-process abuse. Correlate unusual HTTP traffic with process telemetry and inspect for staged exfiltration. Hunt for access to browser credential stores and invalidate exposed credentials quickly. | ||
| NIST SP 800-53 Rev 5 | SI-4 — System Monitoring | Behavioural detection depends on monitoring process, network, and access activity. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Investigators need correlated audit evidence to confirm memory-resident abuse. | |
| Recommendation — Instrument endpoint telemetry to correlate process, network, and collection events. Review correlated audit records to validate suspicious process and access sequences. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | High-fidelity logs are essential when the malware leaves few file artifacts. |
| Recommendation — Centralise endpoint and network logs so memory-only activity remains visible for analysis. | ||
Practitioner Guidance
What to prioritise: Treat process lineage, command-line telemetry, and network destinations as first-class evidence. If a host shows PowerShell abuse plus browser data access or covert POST traffic, escalate even when there is no obvious dropped payload.
What to verify: Confirm whether the suspicious process can reach browser credential stores, screenshot functions, or sensitive APIs, and check whether any credentials or session material were accessed during the same window. If the answer is yes, rotate secrets and invalidate active sessions before you spend time trying to prove persistence.
Practitioner takeaway: For memory-resident stealers, the decisive question is not “did we find the file,” but “did the process get enough runtime access to steal something useful?”
Related resources from NHI Mgmt Group
- What are the signs that a Bumblebee infection is bypassing normal endpoint controls?
- What makes Shai Hulud 2.0 different from a normal npm malware event?
- Why do collaboration attacks like Teams phishing bypass normal controls?
- Why do bot controls fail when automation looks like normal user activity?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org