Lumma is a Russian-based malware-as-a-service threat actor and operator of the Lumma Stealer, also known as LummaC2. Active since 2022, Lumma has built one of the most widespread infostealer ecosystems in the cybercrime landscape, combining a central developer-operated service with a broad affiliate network. The operation has been marketed on Russian-language underground forums and Telegram, and has remained resilient despite major law-enforcement disruption efforts and public exposure campaigns. Lumma primarily conducts financially motivated credential and data theft. Its malware targets browser credentials, cookies, cryptocurrency wallet data, browser extension data, two-factor authentication material, password manager data, remote access tool credentials, payment card information, and broader host and application data. Stolen information is exfiltrated from individuals, enterprises, and government victims and is commonly monetized through underground markets, carding shops, account abuse, and follow-on fraud. Reporting also indicates that Lumma activity has affected U.S. defense industrial base and technology companies. The Lumma ecosystem operates as a mature affiliate-driven service model supported by bulletproof hosting, proxy networks, crypting services, anti-detection tooling, exploit services, messaging platforms, and underground forums. Affiliates have used multiple delivery vectors, including phishing, malicious attachments and links, trojanized applications, compromised websites, exploit kits, fake CAPTCHA verification pages, cloned piracy and adult-content lures, and fraudulent Telegram verification workflows. Observed infection chains have used PowerShell and mshta-based execution, NSIS installers, AutoIt loaders, RC4- and LZNT1-protected payload stages, in-memory execution, and persistence mechanisms. Lumma samples and delivery chains have also demonstrated anti-analysis and defense-evasion features such as obfuscation, API hashing, anti-debugging, anti-VM checks, timing checks, sandbox evasion, and process injection. DLL sideloading and overlay-based payload injection have also been associated with Lumma delivery. Technical analysis of Lumma malware shows capabilities for credential theft, session hijacking through browser cookie theft, host profiling, screenshot capture, registry access, encrypted command-and-control communications, ZIP-compressed exfiltration, and process injection. The malware has used staged loaders and heavily obfuscated code, including control-flow flattening and runtime string decryption. The actor’s infrastructure has repeatedly been disrupted, including a large 2025 domain seizure operation, but Lumma rapidly rebuilt and resumed operations. Later reporting also described a sharp operational decline after an underground doxxing campaign and compromise of Lumma-linked Telegram accounts in 2025, although the broader ecosystem had previously shown strong recovery capacity. Known aliases include LummaC2 and Water Kurita. The operator has also been identified as Shamel, also referred to as Lumma. Lumma affiliates have been observed using additional malware families such as Vidar, Stealc, Meduza Stealer, and possibly CraxsRAT, reflecting a flexible and decentralized criminal ecosystem rather than a single tightly bounded intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer operator hosted by Aeza Group and linked in the article to attacks on the U.S. defense-industrial base and technology companies.
Operates and distributes the Lumma information stealer via MaaS-style campaigns, including fake CAPTCHA lures, phishing, trojanized software, compromised websites, exploit kits, DLL sideloading, and payload injection into legitimate software overlays. The analyzed campaign used social engineering to trick users into pasting malicious PowerShell or mshta commands, leading to staged download, persistence, in-memory execution, credential theft, and exfiltration to C2 infrastructure.
Malware-as-a-service infostealer operation selling Lumma builds and infrastructure to customers; uses obfuscated stealer malware for credential, cookie, wallet, screenshot, and system data theft, with resilient C2 infrastructure that recovered after the May 2025 takedown.
Commercial information-stealer operation whose activity reportedly dropped after a doxxing campaign exposed alleged core members and compromised their Telegram accounts, impacting customer communications and trust.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.