Water Kurita is Trend Micro’s tracking name for the Lumma Stealer malware-as-a-service infostealer operation, also referred to in the content as LummaC2 Stealer, LummaC2, and Storm-2477. The operation has been offered on underground forums since at least August 2022 and is described as a prominent infostealer service. Reported activity includes command-and-control operations, frequent updates, customer support, and use of browser fingerprinting as part of its C2 tactics. The group was targeted by a coordinated international law-enforcement takedown attempt in May 2025, after which it reportedly rebuilt infrastructure and resumed activity. Trend Micro later reported a sharp decline in activity in September 2025, including reduced sample detections, fewer targeted endpoints, and decreased observable C2 activity, coinciding with an underground doxxing campaign against alleged core members and a reported compromise of the group’s Telegram accounts. The doxxing campaign, presented on a site called "Lumma Rats," allegedly exposed personal and operational details of five individuals said to be connected to the operation, including possible administrative, management, development, and crypter-related roles; however, Trend Micro noted that the accuracy of the exposed information and the involvement of the named individuals were not independently verified. Following the disruption, former customers were observed discussing and migrating to alternative infostealer services, particularly Vidar and StealC, and related distribution activity involving Amadey also declined. The content does not attribute Water Kurita to a nation state.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor label used by Trend Micro for activity involving Lumma Stealer; observed evolving C2 tradecraft to include browser fingerprinting and stealthy JavaScript-based data collection/exfiltration.
Operators behind an infostealer MaaS operation experienced a major decline in activity after a doxxing campaign and compromise of their Telegram accounts, disrupting customer communications, C2 activity, and sample detections.
Operators of the Lumma Stealer MaaS infostealer. Activity reportedly declined after a competitor-driven doxxing campaign exposed alleged core members and their Telegram account was reportedly compromised, disrupting customer communications and prompting infrastructure/communications changes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.