lumma
Lumma is a Russia-based malware-as-a-service threat actor active since 2022 and associated with the Lumma Stealer / LummaC2 information stealer. The actor is also linked in the provided content to the developer/operator name Shamel (also "Lumma") and has advertised on Telegram and Russian-language underground forums including RAMP and XSS. Lumma has been described as operating an affiliate-driven MaaS ecosystem and remained active after major 2025 law-enforcement disruption, rebuilding infrastructure and resuming operations. The group’s primary capability is operation of the Lumma infostealer, which steals browser credentials and cookies, cryptocurrency wallet data, browser extension data including MetaMask, 2FA-related data, password manager and remote access tool credentials including KeePass and AnyDesk, credit card data, and broader system and application information. Reported Lumma samples and campaigns used encrypted HTTP POST exfiltration, WinHTTP-based C2 communications, ZIP-compressed data theft, and staged delivery chains. Observed delivery and execution techniques in the provided content include phishing and social engineering, malicious attachments or links, trojanized applications, exploit kits, compromised websites, fake CAPTCHA / ClickFix-style lures that trick victims into pasting malicious PowerShell into Windows Run, mshta execution of JavaScript hidden in disguised media files, NSIS installers, AutoIt loaders, DLL sideloading, overlay injection into legitimate software, in-memory execution, persistence via HKCU Run keys, and anti-analysis or evasion measures such as AMSI-aware decryption logic, anti-debugging, CPUID and RDTSC checks, Heaven’s Gate WoW64 syscall bypass, and mouse-movement-based anti-sandboxing. The content states Lumma targets individuals, organizations, and governments, with common lures involving pirated media, cracked software, adult-content sites, fake Telegram channels, and cryptocurrency-themed verification flows. The broader Lumma ecosystem is supported by affiliates and operational enablers such as proxy services, VPNs, anti-detect browsers, exploit and crypting services, malware-scanning evasion tools, virtual phone/SMS services, offshore or bulletproof hosting, and underground forums and carding shops. Affiliates were also observed using other malware families including Vidar, Stealc, Meduza Stealer, and possibly CraxsRAT. Known aliases directly mentioned in the content include LummaC2 and Water Kurita. The content also references Lumma infrastructure disruption during Operation Endgame and a later underground doxxing campaign ("Lumma Rats") that reportedly exposed core members and disrupted Telegram accounts.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Equity Real Estate Investment Trusts (REITs)
Where they target
Geographies tied to known operations.
- 🇩🇪 Germany
Tradecraft
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates and distributes the Lumma information stealer via MaaS-style campaigns, including fake CAPTCHA lures, phishing, trojanized software, compromised websites, exploit kits, DLL sideloading, and payload injection into legitimate software overlays. The analyzed campaign used social engineering to trick users into pasting malicious PowerShell or mshta commands, leading to staged download, persistence, in-memory execution, credential theft, and exfiltration to C2 infrastructure.
Malware-as-a-service infostealer operation selling Lumma builds and infrastructure to customers; uses obfuscated stealer malware for credential, cookie, wallet, screenshot, and system data theft, with resilient C2 infrastructure that recovered after the May 2025 takedown.
Commercial information-stealer operation whose activity reportedly dropped after a doxxing campaign exposed alleged core members and compromised their Telegram accounts, impacting customer communications and trust.
Malware-as-a-service operation disrupted by law enforcement but resilient, temporarily moving private before resuming public activity; discussed as benefiting from perceived safety in Russia.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.