Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 27 IP / 135 hostnames
Lumma Stealer, also known as LummaC2, is a Windows information-stealing malware-as-a-service operation active since late 2022 and tracked by Trend Micro as Water Kurita.
Profile source: Mallory opens in a new tabLumma Stealer
Lumma Stealer, also known as LummaC2, is a Windows information-stealing malware-as-a-service operation active since late 2022 and tracked by Trend Micro as Water Kurita. It collects browser-resident credentials, saved passwords, authentication cookies, active session artifacts, and credentials stored by local applications. Stolen authenticated browser sessions can be replayed to access online services without a new password, multifactor-authentication, or single-sign-on challenge. The malware has been associated with theft of Claude account sessions, corporate credentials, and OAuth tokens, enabling follow-on account compromise and access to cloud or enterprise environments. Lumma Stealer is distributed through fake software cracks and key generators, malvertising and search-engine manipulation, compromised websites using ClickFix-style fake CAPTCHA lures, deceptive repositories and social-media promotions, and abuse of trusted hosted services. Operators use obfuscation, multistage download chains, and fileless in-memory execution to evade detection. A major law-enforcement disruption in May 2025 temporarily affected its infrastructure, but the operation resumed activity within weeks and continued adapting its hosting and delivery methods.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 1bdbb46e7a4722311e5baefa1eb48cfca30581f1ee597a84b5b43e67f2f2470b 2a8aca9b35d27af25461c87bbbc13b7b54e507ecac2ea031ad6a1a2a68ef1bfa 49dc5155cd50447bbdf92da2045d501ed3424cbd6763f976934430441c23552f 58107ef0590387ecd7870993f6f7166002e92f600238f070f11ff3413cafa800 5f3c032e186823c4f7e419d53167ed992c1c097fe42cbb048be0e25284ff840b Reported operators
Following the sweeping law enforcement operation against Lumma Stealer in early 2025... recent monitoring of Lumma Stealer reveals a steady and quiet resurgence in its activity.
Recently, Hudson Rock analyzed a unique infection from a LummaC2 infostealer log. The victim wasn’t a corporate employee or an unsuspecting consumer. The victim was a high-level North Korean threat actor operating a sophisticated malware development rig.
In this previous campaign, the bitbucket folder contained additional malwares such as Remcos, Sectop RAT, Lumma Stealer, Mars Stealer, and Darktrack RAT.
Storm-2477 [[URL_981dc176_51]] Gruppe in Entwicklung Lumma Dieb
Lumma Stealer, also recognized as LummaC2, Lummac, or simply Lumma, stands as one of the most prominent and rapidly evolving information stealer threats within the global cybersecurity landscape.
The gang uses code-signing for multiple components of their campaign... information stealing malware, like Lumma infostealer
2024-03-07 (THURSDAY): LATRODECTUS INFECTION LEADS TO LUMMA STEALER
Lumma Stealer, also recognized as LummaC2, Lummac, or simply Lumma, stands as one of the most prominent and rapidly evolving information stealer threats within the global cybersecurity landscape.
These IOCs are associated with Truebot campaigns used by Graceful Spider to deliver FlawedGrace and LummaStealer payloads in May of 2023.
The UK is also sanctioning individuals behind Lumma Stealer. The UK government said that Russia has used Lumma Stealer’s stolen credentials to conduct cyber espionage operations against targets globally to support the Kremlin’s objectives.
The UK is also sanctioning individuals behind Lumma Stealer. The UK government said that Russia has used Lumma Stealer’s stolen credentials to conduct cyber espionage operations against targets globally to support the Kremlin’s objectives.
Cybercriminals are exploiting interest in The Odyssey to distribute Lumma Stealer through fake movie downloads... several versions of the Lumma Stealer malware are circulating online, disguised as pirated copies of The Odyssey.
The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.
The cybersecurity company said the activity shares the same high-level playbook as WhiteCobra, another threat cluster that was detected in September 2025 as distributing Lumma Stealer through malicious VS Code extensions.
An employee at Context.ai downloaded compromised scripts containing Lumma Stealer malware, which harvested corporate credentials, active browser session cookies, and stored OAuth tokens resident on the local machine.
A recent campaign, active at least since December 2024, is promoting LummaStealer disguised as cracked software... Upon extraction the final payload is a LummaStealer executable.
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
Among these threats, Lumma Stealer has emerged as a particularly sophisticated player since its introduction in 2022 by the threat actor known as Lumma. Initially marketed as LummaC2, this information stealer quickly gained traction in underground forums, with prices starting at $250.
While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.
Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.
ClearFake has delivered multiple payloads over time, including ArechClient2 and LummaC2; most recently, we’ve observed ACR Stealer, which debuts in this month’s top 10.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
Initial iterations of this campaign distributed Lumma Stealer, before TA585 switched to MonsterV2 in early 2025.
"On May 21, 2025, Europol, FBI, and Microsoft... announced an operation to dismantle the activity of the Lumma infostealer. The malware... is distributed through a malware-as-a-service model."
...has occasionally delivered other payloads including StealC and Lumma Stealer (information stealers with similar functionality to Rhadamanthys).
...but it has also delivered LummaC2 as a tertiary payload.
Check Point researchers have identified multiple malware families distributed through the videos, most of which are infostealers, such as Lumma and Rhadamanythys.
...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.
The following analytic detects BitLockerToGo.exe execution, which has been observed being abused by Lumma stealer malware.
... spread info-stealers such as Lumma Stealer and Vidar Stealer
"...information stealers, such as Atomic (AMOS), Lumma, Rhadamanthys... and Vidar..."
Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.
Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.
Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.
"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."
Bitdefender reported a global resurgence of LummaStealer, coordinated with CastleLoader infrastructure ... spreading through social engineering lures such as fake CAPTCHAs.
Exploited software
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Cybercriminals are distributing Lumma Stealer through fake pirated downloads of Christopher Nolan’s The Odyssey, disguising malicious executables as movie files and in some cases giving them VLC-style icons. Bitdefender reported that the files rely in part on Windows hiding .exe extensions by default, increasing the chance that users will mistake them for legitimate video downloads and launch them. Once executed, Lumma Stealer can harvest browser passwords, cookies, payment card data, cryptocurrency wallet information, autofill records, and remote desktop credentials. Researchers also observed attempted communications with Lumma-linked command-and-control domains including auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click. Lumma is widely tracked as a Russian-developed malware-as-a-service infostealer, enabling multiple criminal operators to reuse the malware in campaigns built around popular lures.
Researchers reported a malicious Visual Studio Code extension campaign using the Solidity Pro name to target Solidity and Web3 developers, stealing cryptocurrency wallet data, developer secrets, and infrastructure credentials. The packages, tied to publishers including helper-beeps and web3devtoolsx, appeared in multiple releases spanning at least versions 1.0.0 through 4.0.0, with some clean-looking intermediate versions likely used to evade marketplace review. Early variants retrieved an encrypted Python payload from Cloudflare Workers after a 12- to 72-hour delay, while later versions evolved into a built-in information stealer. The malware harvested browser data, wallet vaults, GitHub and GitLab tokens, cloud credentials, API keys, SSH private keys, Telegram bot tokens, and secrets linked to wallets including MetaMask, Phantom, Rabby, Coinbase, Trust, and Keplr, then exfiltrated the data through Telegram bot infrastructure. Researchers said the operation used obfuscation, delayed activation, polished branding, and version churn to avoid automated scanning and user suspicion, and noted related malicious VS Code and npm packages as part of a broader developer-focused supply-chain threat in open-source tooling ecosystems.
Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.