Lumma and Risepro Stealer — Browser Credential Access, Injection, and Telegram Exfil
Detects anomalous activity associated with information stealing malware, including unauthorized access to browser credential files (Login Data, Cookies), remote thread injection into browser processes, outbound connections to the Telegram API by non-browser processes, and rapid bulk access to multiple sensitive credential or crypto wallet files.
Microsoft Sentinel (KQL)

