Skip to content

Lumma Stealer

Lumma Stealer, also known as LummaC2, is a Windows information-stealing malware-as-a-service operation active since late 2022 and tracked by Trend Micro as Water Kurita.

Profile source: Mallory opens in a new tab

Lumma Stealer

Family profile

Lumma Stealer, also known as LummaC2, is a Windows information-stealing malware-as-a-service operation active since late 2022 and tracked by Trend Micro as Water Kurita. It collects browser-resident credentials, saved passwords, authentication cookies, active session artifacts, and credentials stored by local applications. Stolen authenticated browser sessions can be replayed to access online services without a new password, multifactor-authentication, or single-sign-on challenge. The malware has been associated with theft of Claude account sessions, corporate credentials, and OAuth tokens, enabling follow-on account compromise and access to cloud or enterprise environments. Lumma Stealer is distributed through fake software cracks and key generators, malvertising and search-engine manipulation, compromised websites using ClickFix-style fake CAPTCHA lures, deceptive repositories and social-media promotions, and abuse of trusted hosted services. Operators use obfuscation, multistage download chains, and fileless in-memory execution to evade detection. A major law-enforcement disruption in May 2025 temporarily affected its infrastructure, but the operation resumed activity within weeks and continued adapting its hosting and delivery methods.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
27 IP / 135 hostnames

Leading locations

  • US75
  • CN9
  • DE5
  • IE4
  • HK3
  • KR3
  • NL3
  • PL2
  • CA1
  • CY1
  • GB1
  • IT1

Leading providers

  • Microsoft Corporation40
  • Amazon.com, Inc.16
  • Amazon.com, Inc.7
  • Google LLC5
  • CHINA UNICOM China169 Backbone2
  • Developed Methods LLC2

Infrastructure traits

  • Hosting 98
  • Anycast 3

Samples

Recent associated samples

Reported operators

Threat actors

39 named in public reporting
Water Kurita

Following the sweeping law enforcement operation against Lumma Stealer in early 2025... recent monitoring of Lumma Stealer reveals a steady and quiet resurgence in its activity.

Lazarus

Recently, Hudson Rock analyzed a unique infection from a LummaC2 infostealer log. The victim wasn’t a corporate employee or an unsuspecting consumer. The victim was a high-level North Korean threat actor operating a sophisticated malware development rig.

UAC-0050

In this previous campaign, the bitbucket folder contained additional malwares such as Remcos, Sectop RAT, Lumma Stealer, Mars Stealer, and Darktrack RAT.

Storm-2477

Storm-2477 [[URL_981dc176_51]] Gruppe in Entwicklung Lumma Dieb

Scattered Spider

Lumma Stealer, also recognized as LummaC2, Lummac, or simply Lumma, stands as one of the most prominent and rapidly evolving information stealer threats within the global cybersecurity landscape.

Black Basta

The gang uses code-signing for multiple components of their campaign... information stealing malware, like Lumma infostealer

Unit 42

2024-03-07 (THURSDAY): LATRODECTUS INFECTION LEADS TO LUMMA STEALER

Angry Likho

Lumma Stealer, also recognized as LummaC2, Lummac, or simply Lumma, stands as one of the most prominent and rapidly evolving information stealer threats within the global cybersecurity landscape.

TA505

These IOCs are associated with Truebot campaigns used by Graceful Spider to deliver FlawedGrace and LummaStealer payloads in May of 2023.

Dragonfly

The UK is also sanctioning individuals behind Lumma Stealer. The UK government said that Russia has used Lumma Stealer’s stolen credentials to conduct cyber espionage operations against targets globally to support the Kremlin’s objectives.

Center 16

The UK is also sanctioning individuals behind Lumma Stealer. The UK government said that Russia has used Lumma Stealer’s stolen credentials to conduct cyber espionage operations against targets globally to support the Kremlin’s objectives.

Russian hacking group

Cybercriminals are exploiting interest in The Odyssey to distribute Lumma Stealer through fake movie downloads... several versions of the Lumma Stealer malware are circulating online, disguised as pirated copies of The Odyssey.

Fox Tempest

The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.

WhiteCobra

The cybersecurity company said the activity shares the same high-level playbook as WhiteCobra, another threat cluster that was detected in September 2025 as distributing Lumma Stealer through malicious VS Code extensions.

ShinyHunters

An employee at Context.ai downloaded compromised scripts containing Lumma Stealer malware, which harvested corporate credentials, active browser session cookies, and stored OAuth tokens resident on the local machine.

Stargazer Goblin

A recent campaign, active at least since December 2024, is promoting LummaStealer disguised as cracked software... Upon extraction the final payload is a LummaStealer executable.

TA2727

Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.

lumma

Among these threats, Lumma Stealer has emerged as a particularly sophisticated player since its introduction in 2022 by the threat actor known as Lumma. Initially marketed as LummaC2, this information stealer quickly gained traction in underground forums, with prices starting at $250.

Storm-3075

While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.

Vanilla Tempest

Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.

ClearFake

ClearFake has delivered multiple payloads over time, including ArechClient2 and LummaC2; most recently, we’ve observed ACR Stealer, which debuts in this month’s top 10.

Storm-0501

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm 2561

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm-0249

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Amadey

Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.

TA585

Initial iterations of this campaign distributed Lumma Stealer, before TA585 switched to MonsterV2 in early 2025.

CoralRaider

"On May 21, 2025, Europol, FBI, and Microsoft... announced an operation to dismantle the activity of the Lumma infostealer. The malware... is distributed through a malware-as-a-service model."

TA547

...has occasionally delivered other payloads including StealC and Lumma Stealer (information stealers with similar functionality to Rhadamanthys).

YouTube Ghost Network

Check Point researchers have identified multiple malware families distributed through the videos, most of which are infostealers, such as Lumma and Rhadamanythys.

Zestix

...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.

Volt Typhoon

The following analytic detects BitLockerToGo.exe execution, which has been observed being abused by Lumma stealer malware.

Sticky Werewolf

... spread info-stealers such as Lumma Stealer and Vidar Stealer

UNC5142

"...information stealers, such as Atomic (AMOS), Lumma, Rhadamanthys... and Vidar..."

Storm-1113

Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.

Storm-1674

Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.

Storm-1607

Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.

HAFNIUM

"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."

TAG-150

Bitdefender reported a global resurgence of LummaStealer, coordinated with CastleLoader infrastructure ... spreading through social engineering lures such as fake CAPTCHAs.

Exploited software

Vulnerabilities linked to Lumma Stealer

1 CVEs

MITRE ATT&CK

Lumma Stealer in ATT&CK

108 distinct techniques

Techniques

108 techniques
T1539 Steal Web Session Cookie T1555.003 Credentials from Web Browsers T1550.004 Web Session Cookie T1078 Valid Accounts T1078.004 Cloud Accounts T1204.002 Malicious File T1105 Ingress Tool Transfer T1082 System Information Discovery T1027 Obfuscated Files or Information T1189 Drive-by Compromise T1036 Masquerading T1199 Trusted Relationship T1059.001 PowerShell T1204 User Execution T1071 Application Layer Protocol T1620 Reflective Code Loading T1566.001 Spearphishing Attachment T1140 Deobfuscate/Decode Files or Information T1218.005 Mshta T1055 Process Injection T1566 Phishing T1059.007 JavaScript T1608.006 SEO Poisoning T1566.002 Spearphishing Link T1550.001 Application Access Token T1001 Data Obfuscation T1584 Compromise Infrastructure T1583 Acquire Infrastructure T1593.001 Social Media T1041 Exfiltration Over C2 Channel T1552.001 Credentials In Files T1583.008 Malvertising T1583.001 Domains T1555 Credentials from Password Stores T1518.001 Security Software Discovery T1055.012 Process Hollowing T1564.003 Hidden Window T1518 Software Discovery T1056.001 Keylogging T1552 Unsecured Credentials T1598 Phishing for Information T1497 Virtualization/Sandbox Evasion T1012 Query Registry T1547 Boot or Logon Autostart Execution T1070 Indicator Removal T1562 Impair Defenses T1027.002 Software Packing T1053 Scheduled Task/Job T1176 Software Extensions T1113 Screen Capture T1571 Non-Standard Port T1567 Exfiltration Over Web Service T1573 Encrypted Channel T1553.002 Code Signing T1106 Native API T1204.003 Malicious Image T1005 Data from Local System T1071.001 Web Protocols T1560 Archive Collected Data T1560.001 Archive via Utility T1008 Fallback Channels T1021.005 VNC T1090.003 Multi-hop Proxy T1547.001 Registry Run Keys / Startup Folder T1562.001 Disable or Modify Tools T1059.003 Windows Command Shell T1090 Proxy T1197 BITS Jobs T1574.001 DLL T1497.001 System Checks T1649 Steal or Forge Authentication Certificates T1195 Supply Chain Compromise T1127.001 MSBuild T1587 Develop Capabilities T1566.003 Spearphishing via Service T1656 Impersonation T1204.001 Malicious Link T1056 Input Capture T1557 Adversary-in-the-Middle T1665 Hide Infrastructure T1583.003 Virtual Private Server T1115 Clipboard Data T1053.005 Scheduled Task T1486 Data Encrypted for Impact T1528 Steal Application Access Token T1003 OS Credential Dumping T1120 Peripheral Device Discovery T1218.007 Msiexec T1614.001 System Language Discovery T1059.010 AutoHotKey & AutoIT T1112 Modify Registry T1546.016 Installer Packages T1059.005 Visual Basic T1564 Hide Artifacts T1568 Dynamic Resolution T1059 Command and Scripting Interpreter T1218 System Binary Proxy Execution T1027.003 Steganography T1543 Create or Modify System Process T1622 Debugger Evasion T1027.007 Dynamic API Resolution T1205 Traffic Signaling T1219 Remote Access Tools T1048 Exfiltration Over Alternative Protocol T1119 Automated Collection T1588 Obtain Capabilities T1586 Compromise Accounts T1020 Automated Exfiltration

Reporting

Research mentioning Lumma Stealer

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 10
Techrepublic Com Security

Fake The Odyssey Downloads Are Hiding Password-Stealing Malware

Cybercriminals are distributing Lumma Stealer through fake pirated downloads of Christopher Nolan’s The Odyssey, disguising malicious executables as movie files and in some cases giving them VLC-style icons. Bitdefender reported that the files rely in part on Windows hiding .exe extensions by default, increasing the chance that users will mistake them for legitimate video downloads and launch them. Once executed, Lumma Stealer can harvest browser passwords, cookies, payment card data, cryptocurrency wallet information, autofill records, and remote desktop credentials. Researchers also observed attempted communications with Lumma-linked command-and-control domains including auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click. Lumma is widely tracked as a Russian-developed malware-as-a-service infostealer, enabling multiple criminal operators to reuse the malware in campaigns built around popular lures.

Aug 10
Cyber Security News

Malicious Solidity Pro VS Code Extension Steals Crypto Wallets, API Keys and SSH Keys via Telegram

Researchers reported a malicious Visual Studio Code extension campaign using the Solidity Pro name to target Solidity and Web3 developers, stealing cryptocurrency wallet data, developer secrets, and infrastructure credentials. The packages, tied to publishers including helper-beeps and web3devtoolsx, appeared in multiple releases spanning at least versions 1.0.0 through 4.0.0, with some clean-looking intermediate versions likely used to evade marketplace review. Early variants retrieved an encrypted Python payload from Cloudflare Workers after a 12- to 72-hour delay, while later versions evolved into a built-in information stealer. The malware harvested browser data, wallet vaults, GitHub and GitLab tokens, cloud credentials, API keys, SSH private keys, Telegram bot tokens, and secrets linked to wallets including MetaMask, Phantom, Rabby, Coinbase, Trust, and Keplr, then exfiltrated the data through Telegram bot infrastructure. Researchers said the operation used obfuscation, delayed activation, polished branding, and version churn to avoid automated scanning and user suspicion, and noted related malicious VS Code and npm packages as part of a broader developer-focused supply-chain threat in open-source tooling ecosystems.

Aug 10
The Hacker News

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Aug 5
Malware News

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - Malware News - Malware Analysis, News and Indicators

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty in U.S. federal court for his role in a Snowflake-linked hacking and extortion campaign that compromised at least 165 organizations and exposed data tied to at least 100 million people. Prosecutors said the group used stolen credentials between February and October 2024 to access cloud-hosted customer environments, steal terabytes of sensitive data and billions of files, and extort victims by threatening to publish the information. Reported victims included AT&T, Ticketmaster, Advance Auto Parts, Neiman Marcus, Santander, and LendingTree, with stolen records including banking data, Social Security numbers, passport numbers, driver’s license numbers, and DEA registration numbers. Investigators said the intrusions were not caused by a compromise of Snowflake itself but by previously exposed customer credentials, many traced to infostealer malware infections dating back to 2020. Mandiant found that at least 79.7% of the accounts used in the campaign had prior credential exposure, and observed the attackers using Snowflake’s SnowSight web interface, the SnowSQL CLI, DBeaver Ultimate, and a reconnaissance utility tracked as FROSTBITE to enumerate users, roles, IPs, session IDs, and organization names. Authorities said the conspiracy generated more than $2.5 million in ransom payments, while Moucka separately made about $495,000 selling stolen data on cybercrime forums; he was extradited to the United States and is scheduled to be sentenced on October 27, 2026.

Aug 5
Data Breaches

Canadian Man Pleads Guilty to Hacking U.S. Cloud Storage Provider and Extorting Its Customers for Millions - DataBreaches.Net

Aug 5
Bleeping Computer

Canadian pleads guilty to Snowflake cloud data-theft attacks

Aug 5
Cyberscoop

Snowflake hacker pleads guilty, faces up to 32 years in prison | CyberScoop

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.