This cluster describes a sophisticated malware campaign distributing Lumma Stealer, a data-stealing malware, through GitHub infrastructure. The campaign also involved other malware variants, including SectopRAT, Vidar, and Cobeacon. The attackers abused GitHub’s release infrastructure for initial access and utilized Tactics, Techniques and Procedures (TTPs) that exhibit significant overlaps with those used by the Stargazer Goblin group.