LummaStealer is an infostealer malware family used to steal credentials and support follow-on intrusion activity. The provided content states that it was delivered by the threat actor Vane Viper via fake CAPTCHA lures, using malicious adtech and traffic distribution system (TDS) infrastructure to evade detection and reach victims. The malware is also explicitly linked to the Snowflake breach, where threat actors used LummaStealer in initial access against affected organizations. More broadly, the content places LummaStealer within the infostealer ecosystem that fuels credential abuse, account compromise, and ransomware operations by harvesting credentials later used or traded by threat actors. High-confidence behaviors and context directly mentioned include credential theft, use in initial access, delivery through fake CAPTCHA social engineering, and association with malicious adtech/TDS campaigns. Targeting details are not specific to LummaStealer alone in the content, but the surrounding reporting ties infostealer-driven compromises to enterprise and non-managed/BYOD devices and to breaches affecting multiple sectors. No malware-specific file, network, or hash IOCs are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
LummaStealer is an infostealer malware designed to steal information such as stored passwords, cookies, and other sensitive data from compromised systems. It is distributed via malicious adtech and traffic distribution systems (TDS), often hidden behind deceptive mechanisms like fake CAPTCHAs.
LummaStealer is an infostealer malware used to steal credentials, cookies, and other sensitive information from victim systems. It is commonly used as an initial access vector for further attacks, including ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.