Skip to content
Malware family Windows

Lumma Stealer

Lumma Stealer, also tracked as LummaC2 or LummaC, is a Windows information-stealing malware family written in C++ and active since at least 2022.

Profile source: Mallory opens in a new tab

Lumma Stealer

Family profile

Lumma Stealer, also tracked as LummaC2 or LummaC, is a Windows information-stealing malware family written in C++ and active since at least 2022. It is widely operated under a malware-as-a-service model and has become one of the most broadly deployed commodity stealers in the cybercrime ecosystem. The malware is designed to harvest sensitive data from compromised systems, including browser-stored credentials, cookies, session tokens, autofill data, and cryptocurrency wallet information. Reporting also associates Lumma with large-scale credential theft that has subsequently been used to support follow-on criminal activity and, in some cases, cyber-espionage operations.

Lumma is frequently distributed through social-engineering and malware-delivery ecosystems rather than through self-contained exploitation. Observed delivery vectors include ClickFix lures that trick users into pasting and executing malicious commands, malvertising, fake cracked-software downloads, SEO-poisoned pages promoting pirated software or keygens, and drive-by delivery through third-party loaders. It has also been linked to broader MaaS and loader infrastructures such as Factory-v3 and Dolphin Loader, indicating use by multiple affiliates and operators.

On infected hosts, Lumma focuses on credential and session theft from browsers and related applications. It is commonly discussed alongside stealer-log markets because stolen data is packaged and monetized at scale. The family is actively maintained, with frequent updates intended to evade browser protections and defensive tooling. Observed campaigns and sandboxed samples also show supporting behaviors such as persistence, system and software discovery, and process injection or tampering. In some delivery chains, Lumma has been deployed through masqueraded installers and remote-management abuse.

Lumma has been prominent enough to attract coordinated law-enforcement disruption and sanctions activity. Public reporting states that international action against LummaC2 infrastructure began in 2025, and later sanctions targeted developers and operators linked to the service. Government statements have further asserted that credentials stolen via Lumma were used by Russian state actors to support espionage against global targets. Victimology spans consumers, enterprises, and small and medium-sized businesses, with broad global distribution and especially heavy impact on Windows environments.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 20, 2026
Feed role
C2
Host form
2 IP / 116 hostnames

Leading locations

  • US47
  • IE3
  • LU1
  • SC1

Leading providers

  • Microsoft Corporation26
  • Amazon.com, Inc.15
  • Amazon.com, Inc.7
  • Google LLC2
  • Ghosty Networks LLC1

Infrastructure traits

  • Hosting 51
  • Vpn 2

Samples

Recent associated samples

Reported operators

Threat actors

31 named in public reporting
ShinyHunters

An employee at Context.ai downloaded compromised scripts containing Lumma Stealer malware, which harvested corporate credentials, active browser session cookies, and stored OAuth tokens resident on the local machine.

Storm-2477

And the most prolific tool for stealing it, until law enforcement hit it in 2025, was a piece of malware called Lumma. Lumma (also known as LummaC2) isn't a single cybercrime gang—it is a commercial product.

Stargazer Goblin

A recent campaign, active at least since December 2024, is promoting LummaStealer disguised as cracked software... Upon extraction the final payload is a LummaStealer executable.

Scattered Spider

Additional tradecraft and techniques: Usage of open-source tooling: ScreenConnect, FleetDeck, AnyDesk, RustDesk, Splashtop, Pulseway, TightVNC, LummaC2, Level.io, Mesh, TacticalRMM, Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.

TA2727

Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.

lumma

Among these threats, Lumma Stealer has emerged as a particularly sophisticated player since its introduction in 2022 by the threat actor known as Lumma. Initially marketed as LummaC2, this information stealer quickly gained traction in underground forums, with prices starting at $250.

Angry Likho

We examined this payload and concluded that it is the Lumma Trojan stealer (Trojan-PSW.Win32.Lumma). The Lumma stealer gathers system and installed software information from the compromised devices, as well as sensitive data such as cookies, usernames, passwords, banking card numbers, and connection logs.

Storm-3075

While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.

Vanilla Tempest

Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.

Fox Tempest

Microsoft linked Fox Tempest-enabled activity to ransomware and malware operations involving Vanilla Tempest, Rhysida, Oyster, Lumma Stealer, Vidar, INC, Qilin, Akira, and other families or affiliates.

ClearFake

ClearFake has delivered multiple payloads over time, including ArechClient2 and LummaC2; most recently, we’ve observed ACR Stealer, which debuts in this month’s top 10.

Storm-0501

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm 2561

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Storm-0249

Associated malware includes Rhysida ransomware, Lumma Stealer, Vidar infostealer, and the Oyster (Broomstick) backdoor.

Amadey

Amadey is a modular Windows botnet sold as MaaS by author "InCrease" on XSS/Exploit forums, active since 2018. It commonly drops Lumma, StealC, RedLine, CoinMiners, and RATs.

UAC-0050

Proofpoint has also seen the .zip contain an executable that loaded Lumma Stealer.

TA585

Initial iterations of this campaign distributed Lumma Stealer, before TA585 switched to MonsterV2 in early 2025.

Water Kurita

Offered on underground forums as malware-as-a-service (MaaS) since at least August 2022, Lumma Stealer (also known as LummaC2 Stealer or LummaC2) has been one of the most prominent information stealers this year.

CoralRaider

"On May 21, 2025, Europol, FBI, and Microsoft... announced an operation to dismantle the activity of the Lumma infostealer. The malware... is distributed through a malware-as-a-service model."

TA547

...has occasionally delivered other payloads including StealC and Lumma Stealer (information stealers with similar functionality to Rhadamanthys).

YouTube Ghost Network

Check Point researchers have identified multiple malware families distributed through the videos, most of which are infostealers, such as Lumma and Rhadamanythys.

Zestix

...relied on distributing infostealers such as RedLine, Lumma, or Vidar... to harvest credentials.

Volt Typhoon

The following analytic detects BitLockerToGo.exe execution, which has been observed being abused by Lumma stealer malware.

UNC5142

"...information stealers, such as Atomic (AMOS), Lumma, Rhadamanthys... and Vidar..."

Storm-1113

Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.

Storm-1674

Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.

Storm-1607

Bitdefender reports a surge in LummaStealer activity, showing the MaaS infostealer rebounded after 2025 law enforcement disruption... Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer designed to steal sensitive data like passwords, credit card info, and crypto wallet keys.

HAFNIUM

"CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments."

GrayBravo

Bitdefender reported a global resurgence of LummaStealer, coordinated with CastleLoader infrastructure ... spreading through social engineering lures such as fake CAPTCHAs.

Exploited software

Vulnerabilities linked to Lumma Stealer

1 CVEs

MITRE ATT&CK

Lumma Stealer in ATT&CK

103 distinct techniques

Techniques

103 techniques
T1539 Steal Web Session Cookie T1566 Phishing T1555.003 Credentials from Web Browsers T1204 User Execution T1105 Ingress Tool Transfer T1608.006 SEO Poisoning T1656 Impersonation T1059.001 PowerShell T1649 Steal or Forge Authentication Certificates T1005 Data from Local System T1486 Data Encrypted for Impact T1528 Steal Application Access Token T1003 OS Credential Dumping T1555 Credentials from Password Stores T1204.002 Malicious File T1189 Drive-by Compromise T1566.002 Spearphishing Link T1041 Exfiltration Over C2 Channel T1012 Query Registry T1120 Peripheral Device Discovery T1082 System Information Discovery T1518.001 Security Software Discovery T1218.007 Msiexec T1547.001 Registry Run Keys / Startup Folder T1614.001 System Language Discovery T1059.010 AutoHotKey & AutoIT T1112 Modify Registry T1546.016 Installer Packages T1027 Obfuscated Files or Information T1078 Valid Accounts T1218.005 Mshta T1059.005 Visual Basic T1562 Impair Defenses T1140 Deobfuscate/Decode Files or Information T1564 Hide Artifacts T1547 Boot or Logon Autostart Execution T1568 Dynamic Resolution T1553.002 Code Signing T1059 Command and Scripting Interpreter T1071 Application Layer Protocol T1059.003 Windows Command Shell T1497 Virtualization/Sandbox Evasion T1218 System Binary Proxy Execution T1027.003 Steganography T1543 Create or Modify System Process T1059.007 JavaScript T1560 Archive Collected Data T1036 Masquerading T1622 Debugger Evasion T1055 Process Injection T1115 Clipboard Data T1071.001 Web Protocols T1620 Reflective Code Loading T1027.007 Dynamic API Resolution T1562.001 Disable or Modify Tools T1583 Acquire Infrastructure T1566.001 Spearphishing Attachment T1583.008 Malvertising T1567 Exfiltration Over Web Service T1205 Traffic Signaling T1584 Compromise Infrastructure T1219 Remote Access Tools T1048 Exfiltration Over Alternative Protocol T1518 Software Discovery T1056.001 Keylogging T1119 Automated Collection T1204.003 Malicious Image T1588 Obtain Capabilities T1106 Native API T1586 Compromise Accounts T1020 Automated Exfiltration T1057 Process Discovery T1113 Screen Capture T1583.001 Domains T1204.001 Malicious Link T1132.001 Standard Encoding T1587.001 Malware T1027.001 Binary Padding T1217 Browser Information Discovery T1027.013 Encrypted/Encoded File T1583.006 Web Services T1047 Windows Management Instrumentation T1124 System Time Discovery T1573.001 Symmetric Cryptography T1027.016 Junk Code Insertion T1008 Fallback Channels T1102.001 Dead Drop Resolver T1497.003 Time Based Checks T1608.001 Upload Malware T1129 Shared Modules T1021.002 SMB/Windows Admin Shares T1497.001 System Checks T1027.002 Software Packing T1566.003 Spearphishing via Service T1218.011 Rundll32 T1090 Proxy T1110.004 Credential Stuffing T1056 Input Capture T1556 Modify Authentication Process T1074 Data Staged T1573 Encrypted Channel T1559.001 Component Object Model T1185 Browser Session Hijacking

Reporting

Research mentioning Lumma Stealer

Jul 20
Zdnet

Qui sont les pirates russes visés par les nouvelles sanctions eur ...

Visé l’an dernier par l’opération Endgame, l’infostealer Lumma refait parler de lui dans cette liste à la faveur de mesures visant deux cybercriminels.

Jul 20
Malware News

Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding - Malware News - Malware Analysis, News and Indicators

RenPy Loader has also been observed delivering other malware, including HijackLoader and Lumma Stealer, showing that the final payload can vary between campaigns.

Jul 20
Malwarebytes Labs

Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding | Malwarebytes

RenPy Loader has also been observed delivering other malware, including HijackLoader and Lumma Stealer, showing that the final payload can vary between campaigns.

Jul 18
Cyberveille

ClickFix : une méthodologie d'attaque industrialisée invisible aux EDR et antivirus | CyberVeille

Payloads observés # Lumma Stealer (payload le plus fréquent)

Jul 15
Help Net Security

ClickFix is changing the economics of social engineering - Help Net Security

Lumma Stealer is the most prolific ClickFix payload, but the payload catalog is expanding well beyond it, researchers found.

Jul 14
Chainalysis

“Stern” Ransomware Operator Sanctioned by EU

The EU designated individuals and entities linked to LummaC2 infostealer malware... LummaC2 was taken down by the United States’ Department of Justice (DOJ), Europol’s European Cybercrime Center, and Japan’s Cybercrime Control Center in a coordinated effort that began in May 2025.

Jul 14
Ahnlab Asec

June 2026 Infostealer Trend Report - ASEC

In June, Remus, ACRStealer, LummaC2, and Vidar were distributed.

Jul 14
The Hacker News

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

The sanctions are also aimed at individuals behind Lumma Stealer for enabling cybercriminals to collect sensitive information from compromised devices at scale.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.