Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
1 malware family

lumma

Also known asLumma

Lumma is a Russia-based malware-as-a-service threat actor active since 2022 and associated with the Lumma Stealer / LummaC2 information stealer. The actor is also linked in the provided content to the developer/operator name Shamel (also "Lumma") and has advertised on Telegram and Russian-language underground forums including RAMP and XSS. Lumma has been described as operating an affiliate-driven MaaS ecosystem and remained active after major 2025 law-enforcement disruption, rebuilding infrastructure and resuming operations. The group’s primary capability is operation of the Lumma infostealer, which steals browser credentials and cookies, cryptocurrency wallet data, browser extension data including MetaMask, 2FA-related data, password manager and remote access tool credentials including KeePass and AnyDesk, credit card data, and broader system and application information. Reported Lumma samples and campaigns used encrypted HTTP POST exfiltration, WinHTTP-based C2 communications, ZIP-compressed data theft, and staged delivery chains. Observed delivery and execution techniques in the provided content include phishing and social engineering, malicious attachments or links, trojanized applications, exploit kits, compromised websites, fake CAPTCHA / ClickFix-style lures that trick victims into pasting malicious PowerShell into Windows Run, mshta execution of JavaScript hidden in disguised media files, NSIS installers, AutoIt loaders, DLL sideloading, overlay injection into legitimate software, in-memory execution, persistence via HKCU Run keys, and anti-analysis or evasion measures such as AMSI-aware decryption logic, anti-debugging, CPUID and RDTSC checks, Heaven’s Gate WoW64 syscall bypass, and mouse-movement-based anti-sandboxing. The content states Lumma targets individuals, organizations, and governments, with common lures involving pirated media, cracked software, adult-content sites, fake Telegram channels, and cryptocurrency-themed verification flows. The broader Lumma ecosystem is supported by affiliates and operational enablers such as proxy services, VPNs, anti-detect browsers, exploit and crypting services, malware-scanning evasion tools, virtual phone/SMS services, offshore or bulletproof hosting, and underground forums and carding shops. Affiliates were also observed using other malware families including Vidar, Stealc, Meduza Stealer, and possibly CraxsRAT. Known aliases directly mentioned in the content include LummaC2 and Water Kurita. The content also references Lumma infrastructure disruption during Operation Endgame and a later underground doxxing campaign ("Lumma Rats") that reportedly exposed core members and disrupted Telegram accounts.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Equity Real Estate Investment Trusts (REITs)

Where they target

Geographies tied to known operations.

  • 🇩🇪 Germany
MITRE ATT&CK

Tradecraft

39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics45 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
TA0001
Initial Access
2 techniques
T1189
Drive-by Compromise
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0002
Execution
4 techniques
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.005
Visual Basic
T1059.007
JavaScript
T1129
Shared Modules
T1204
User Execution
T1204.002
Malicious File
T1559
Inter-Process Communication
T1559.001
Component Object Model
TA0003
Persistence
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
7 techniques
T1027
Obfuscated Files or Information
T1027.002
Software Packing
T1036
Masquerading
T1140
Deobfuscate/Decode Files or Information
T1218
System Binary Proxy Execution
T1218.005
Mshta
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
T1497.003
Time Based Checks
T1564
Hide Artifacts
T1620
Reflective Code Loading
TA0006
Credential Access
2 techniques
T1539
Steal Web Session Cookie
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
TA0007
Discovery
2 techniques
T1057
Process Discovery
T1497
Virtualization/Sandbox Evasion
T1497.001
System Checks
T1497.003
Time Based Checks
TA0009
Collection
2 techniques
T1185
Browser Session Hijacking
T1560
Archive Collected Data
TA0011
Command and Control
4 techniques
T1008
Fallback Channels
T1071×2
Application Layer Protocol
T1071.001
Web Protocols
T1105
Ingress Tool Transfer
T1568
Dynamic Resolution
TA0010
Exfiltration
1 technique
T1041×2
Exfiltration Over C2 Channel
IOCS

Observables

17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

securelistNews
May 21, 2026
How Lumma Stealer sneaks into organizations | Securelist

Operates and distributes the Lumma information stealer via MaaS-style campaigns, including fake CAPTCHA lures, phishing, trojanized software, compromised websites, exploit kits, DLL sideloading, and payload injection into legitimate software overlays. The analyzed campaign used social engineering to trick users into pasting malicious PowerShell or mshta commands, leading to staged download, persistence, in-memory execution, credential theft, and exfiltration to C2 infrastructure.

Read more
breakglass intelNews
Mar 5, 2026
LummaC2 v4.0 Dissected: CFF Obfuscation, Heaven's Gate Syscalls, and Trigonometric Anti-Sandbox in a MaaS Infostealer - Breakglass Intelligence - Breakglass Intelligence

Malware-as-a-service infostealer operation selling Lumma builds and infrastructure to customers; uses obfuscated stealer malware for credential, cookie, wallet, screenshot, and system data theft, with resilient C2 infrastructure that recovered after the May 2025 takedown.

Read more
the hacker newsNews
Oct 23, 2025
ThreatsDay Bulletin: $176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More

Commercial information-stealer operation whose activity reportedly dropped after a doxxing campaign exposed alleged core members and compromised their Telegram accounts, impacting customer communications and trust.

Read more
recorded future blogNews
Oct 23, 2025
Dark Covenant 3.0: Controlled Impunity and Russia’s Cybercriminals

Malware-as-a-service operation disrupted by law enforcement but resilient, temporarily moving private before resuming public activity; discussed as benefiting from perceived safety in Russia.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping39

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables17

Domains, IPs, and hashes tied to this actor, refreshed continuously.