Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2
- Host form
- 2 IP / 116 hostnames
Lumma Stealer, also tracked as LummaC2 or LummaC, is a Windows information-stealing malware family written in C++ and active since at least 2022.
Profile source: Mallory opens in a new tabLumma Stealer
Lumma Stealer, also tracked as LummaC2 or LummaC, is a Windows information-stealing malware family written in C++ and active since at least 2022. It is widely operated under a malware-as-a-service model and has become one of the most broadly deployed commodity stealers in the cybercrime ecosystem. The malware is designed to harvest sensitive data from compromised systems, including browser-stored credentials, cookies, session tokens, autofill data, and cryptocurrency wallet information. Reporting also associates Lumma with large-scale credential theft that has subsequently been used to support follow-on criminal activity and, in some cases, cyber-espionage operations.
Lumma is frequently distributed through social-engineering and malware-delivery ecosystems rather than through self-contained exploitation. Observed delivery vectors include ClickFix lures that trick users into pasting and executing malicious commands, malvertising, fake cracked-software downloads, SEO-poisoned pages promoting pirated software or keygens, and drive-by delivery through third-party loaders. It has also been linked to broader MaaS and loader infrastructures such as Factory-v3 and Dolphin Loader, indicating use by multiple affiliates and operators.
On infected hosts, Lumma focuses on credential and session theft from browsers and related applications. It is commonly discussed alongside stealer-log markets because stolen data is packaged and monetized at scale. The family is actively maintained, with frequent updates intended to evade browser protections and defensive tooling. Observed campaigns and sandboxed samples also show supporting behaviors such as persistence, system and software discovery, and process injection or tampering. In some delivery chains, Lumma has been deployed through masqueraded installers and remote-management abuse.
Lumma has been prominent enough to attract coordinated law-enforcement disruption and sanctions activity. Public reporting states that international action against LummaC2 infrastructure began in 2025, and later sanctions targeted developers and operators linked to the service. Government statements have further asserted that credentials stolen via Lumma were used by Russian state actors to support espionage against global targets. Victimology spans consumers, enterprises, and small and medium-sized businesses, with broad global distribution and especially heavy impact on Windows environments.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fd3e4fed8a88f9aa00a921cbb6fb564aa64943b20fc512ce3eb134d5ebfd2d3 401b70e0313d7f6dd1fd444a8d61e25ae433a5944a2607405fe5ddbc9b8f7afc 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac b4a3205341b7d6eee7d8a810300a39960ac66c7fb89f585a06c6e1e921a49820 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 c28e177f4a96a97f256b5919631a3aa1c2bd64e1ee193f9a47a8fa70dbb5fd8d 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 Reported operators
An employee at Context.ai downloaded compromised scripts containing Lumma Stealer malware, which harvested corporate credentials, active browser session cookies, and stored OAuth tokens resident on the local machine.
And the most prolific tool for stealing it, until law enforcement hit it in 2025, was a piece of malware called Lumma. Lumma (also known as LummaC2) isn't a single cybercrime gang—it is a commercial product.
A recent campaign, active at least since December 2024, is promoting LummaStealer disguised as cracked software... Upon extraction the final payload is a LummaStealer executable.
Additional tradecraft and techniques: Usage of open-source tooling: ScreenConnect, FleetDeck, AnyDesk, RustDesk, Splashtop, Pulseway, TightVNC, LummaC2, Level.io, Mesh, TacticalRMM, Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
Among these threats, Lumma Stealer has emerged as a particularly sophisticated player since its introduction in 2022 by the threat actor known as Lumma. Initially marketed as LummaC2, this information stealer quickly gained traction in underground forums, with prices starting at $250.
We examined this payload and concluded that it is the Lumma Trojan stealer (Trojan-PSW.Win32.Lumma). The Lumma stealer gathers system and installed software information from the compromised devices, as well as sensitive data such as cookies, usernames, passwords, banking card numbers, and connection logs.
While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.
Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.
Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.
ClearFake has delivered multiple payloads over time, including ArechClient2 and LummaC2; most recently, we’ve observed ACR Stealer, which debuts in this month’s top 10.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.
Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.
Proofpoint has also seen the .zip contain an executable that loaded Lumma Stealer.
Initial iterations of this campaign distributed Lumma Stealer, before TA585 switched to MonsterV2 in early 2025.
Offered on underground forums as malware-as-a-service (MaaS) since at least August 2022, Lumma Stealer (also known as LummaC2 Stealer or LummaC2) has been one of the most prominent information stealers this year.
"On May 21, 2025, Europol, FBI, and Microsoft... announced an operation to dismantle the activity of the Lumma infostealer. The malware... is distributed through a malware-as-a-service model."
...has occasionally delivered other payloads including StealC and Lumma Stealer (information stealers with similar functionality to Rhadamanthys).
...but it has also delivered LummaC2 as a tertiary payload.
Check Point researchers have identified multiple malware families distributed through the videos, most of which are infostealers, such as Lumma and Rhadamanythys.
...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.
The following analytic detects BitLockerToGo.exe execution, which has been observed being abused by Lumma stealer malware.
... spread info-stealers such as Lumma Stealer and Vidar Stealer
"...information stealers, such as Atomic (AMOS), Lumma, Rhadamanthys... and Vidar..."
Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.
Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.
Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.
"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."
Bitdefender reported a global resurgence of LummaStealer, coordinated with CastleLoader infrastructure ... spreading through social engineering lures such as fake CAPTCHAs.
Exploited software
MITRE ATT&CK
Reporting
Visé l’an dernier par l’opération Endgame, l’infostealer Lumma refait parler de lui dans cette liste à la faveur de mesures visant deux cybercriminels.
RenPy Loader has also been observed delivering other malware, including HijackLoader and Lumma Stealer, showing that the final payload can vary between campaigns.
RenPy Loader has also been observed delivering other malware, including HijackLoader and Lumma Stealer, showing that the final payload can vary between campaigns.
Payloads observés # Lumma Stealer (payload le plus fréquent)
Lumma Stealer is the most prolific ClickFix payload, but the payload catalog is expanding well beyond it, researchers found.
The EU designated individuals and entities linked to LummaC2 infostealer malware... LummaC2 was taken down by the United States’ Department of Justice (DOJ), Europol’s European Cybercrime Center, and Japan’s Cybercrime Control Center in a coordinated effort that began in May 2025.
In June, Remus, ACRStealer, LummaC2, and Vidar were distributed.
The sanctions are also aimed at individuals behind Lumma Stealer for enabling cybercriminals to collect sensitive information from compromised devices at scale.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.