Lumma Stealer is a financially motivated cybercriminal operation centered on a malware-as-a-service information stealer targeting Windows systems. It is widely tracked under names including LummaStealer, lumma_stealer_group, lumma_stealer_operators, and lumma_stealer_team. The operation has been one of the most prevalent infostealer threats observed in 2025 and is associated with large-scale theft of credentials, session material, cryptocurrency wallet data, and other sensitive information that can be monetized directly or sold to other criminal actors, including initial access brokers and ransomware affiliates. The group relies heavily on scalable social-engineering-driven distribution rather than exclusive dependence on software exploitation. Reported delivery methods include pirated and cracked software ecosystems, adult-content lures, fake channels impersonating software-sharing communities, and deceptive verification workflows. A prominent tactic is ClickFix, in which victims are tricked by fake CAPTCHA or troubleshooting prompts into manually executing malicious commands, often using native Windows scripting and application execution mechanisms. This approach helps bypass defenses focused primarily on malicious file downloads and conventional attachment-based delivery. Operationally, Lumma Stealer campaigns have used loader infrastructure such as CastleLoader to stage payload delivery, improve evasion, and allow rapid replacement of payloads and command-and-control infrastructure. The malware has been associated with techniques including DLL side-loading and overlay injection, and reporting has described ongoing adaptation in loaders, hosting, and delivery chains to maintain resilience under disruption pressure. The operation has also been described as maintaining a marketplace-oriented ecosystem for stolen data and customer support consistent with mature cybercrime service models. Lumma Stealer has shown notable resilience following coordinated law-enforcement action in 2025 that disrupted parts of its infrastructure. Subsequent activity indicated rapid migration to new providers, use of alternative loaders, and a shift toward more discreet distribution channels and stealthier evasion tactics. This recovery underscores the durability of profitable MaaS ecosystems when demand for stolen credentials remains high. The threat is significant not only for direct credential theft but also because stolen data from Lumma Stealer infections can enable downstream account takeover, fraud, cloud and SaaS compromise, and ransomware intrusion. The operation is best characterized as a major criminal infostealer service rather than a nation-state actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operators behind the LummaStealer malware-as-a-service (MaaS) infostealer are resurging post-2025 disruption, shifting toward social-engineering-heavy infection chains (notably fake CAPTCHA ‘ClickFix’ prompts that induce users to copy/paste malicious commands) and leveraging CastleLoader as a flexible delivery mechanism to swap payloads and C2 infrastructure to evade detection.
Information stealer targeting credentials and cryptocurrency wallets, using browser fingerprinting and secondary payloads, with high-volume infections via diverse delivery methods.
Operators of Lumma Stealer provided malware-as-a-service, infecting hundreds of thousands of Windows computers globally to steal information.
Operators of Lumma Stealer are responsible for the majority of infostealer infections observed, targeting credentials and session tokens to facilitate further compromise or sale of access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.