Water Kurita is a cybercriminal intrusion set associated with the Lumma Stealer malware-as-a-service operation and linked by some reporting to the alias Storm-2477. The actor has been active since at least 2022 through operations centered on credential and information theft, using Lumma Stealer as a scalable commercial infostealer platform. Water Kurita has shown resilience after disruption, including recovery following a major 2025 law-enforcement action against Lumma-related infrastructure, followed later by a marked operational decline amid an underground doxxing campaign and compromise of operator communications. The actor’s tradecraft emphasizes mass malware distribution, credential theft, data exfiltration, and defense evasion. Reported delivery methods for Lumma-associated activity include fake software cracks and key generators, malvertising and search-engine manipulation, compromised websites presenting ClickFix-style fake CAPTCHA lures, social-media promotion of trojanized software, and repositories on developer platforms masquerading as legitimate tools. In observed ClickFix chains, victims were induced to execute malicious PowerShell that decrypted and launched payloads in memory, enabling fileless execution. Water Kurita-associated Lumma infrastructure also used browser fingerprinting and traffic-filtering logic to profile victims before delivering payloads. The actor adapted infrastructure after the 2025 takedown by shifting away from prior heavy reliance on reverse-proxy services and diversifying hosting providers. Reporting also describes use of command-and-control mechanisms and malware staging designed to complicate disruption and attribution. Water Kurita’s operations are financially oriented and fit the malware-as-a-service ecosystem, with customer support, frequent updates, and broad criminal distribution channels contributing to Lumma Stealer’s prominence. Researchers have also linked Water Kurita to an apparent follow-on distribution campaign known as FakeGit. That campaign used thousands of counterfeit developer-platform repositories and fake developer personas, increasingly themed around AI tools, skills, agents, workflows, and Model Context Protocol servers, to distribute SmartLoader and ultimately the StealC infostealer. In that activity, malicious archives launched a LuaJIT-based loader and obfuscated Lua scripts; SmartLoader then established persistence via scheduled tasks, retrieved command-and-control information through a Polygon smart contract, downloaded encrypted payloads from code-hosting services, and deployed StealC. This suggests an evolution from Lumma-centric distribution toward broader infostealer delivery operations that exploit trust in open-source and AI-assisted software discovery ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealer malware operation experiencing a sharp decline in C2 activity, sample detections, and targeted endpoints after a doxxing/exposure campaign and compromise of its Telegram accounts disrupted operators and customer communications.
Operators/developers behind Lumma Stealer who rapidly rebuilt infrastructure and resumed campaigns after the 2025 law-enforcement takedown, using delivery methods including fake cracks/keygens, ClickFix fake CAPTCHA lures, GitHub-hosted malware, and social-media-driven distribution.
Referenced as the actor previously linked to an earlier Lumma stealer distribution campaign that researchers believe FakeGit may continue.
Referenced as the threat actor previously associated with an earlier malware operation that FakeGit is believed to have evolved from; the current campaign uses counterfeit GitHub repositories masquerading as AI tools and MCP servers to distribute malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.