Lumma Stealer, also widely referred to as LummaC2, is a subscription-based malware-as-a-service infostealer that has been one of the most active commodity credential-theft families in the cybercrime ecosystem. It is designed to harvest sensitive data from compromised systems, especially browser-stored credentials, session cookies, autofill data, and other information that can be monetized for account takeover, fraud, and follow-on intrusion activity. Reporting also associates it with theft of cryptocurrency wallet data and other confidential user information.
Lumma is prevalent in large-scale criminal campaigns and is commonly used as an access-enabling malware family rather than as a final objective in itself. Stolen data from Lumma infections has been used to compromise cloud and enterprise accounts, including file-sharing and SaaS environments, and to support broader cybercrime operations. The malware has been discussed alongside other commodity stealers such as Vidar, RedLine, Rhadamanthys, and StealC, reflecting its role in the stealer-log marketplace and initial-access economy.
Observed delivery methods include fake CAPTCHA and ClickFix-style social engineering, trojanized or malicious downloads distributed through repositories and video-linked lures, fake installers, cracked-software ecosystems, phishing-led delivery, and malware chains in which loaders or staged installers ultimately deploy Lumma as the final payload. It has also appeared as a downstream payload in multi-stage infections involving loaders such as RenPy Loader and in campaigns using shared distribution infrastructure that hosts multiple infostealer families.
Lumma primarily targets Windows environments in the supplied reporting. Its core behavior is consistent with credential theft and session hijacking through collection of browser secrets and active-session material, followed by exfiltration to operator-controlled infrastructure. The family has been linked in reporting to Russian cybercrime activity and to infrastructure providers that allegedly supported infostealer operations. Law-enforcement and private-sector disruption efforts have targeted parts of its infrastructure, but Lumma has continued to resurface in active campaigns with evolving delivery tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-1731 BeyondTrust RS/PRA 9.8 Yes (GitHub) Yes (BT26-02) ... CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments.
31 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It is believed that FakeGit is an evolution of a previous malware operation that was previously associated with Water Kurita and that used Lumma Stealer.
An employee at Context.ai downloaded compromised scripts containing Lumma Stealer malware, which harvested corporate credentials, active browser session cookies, and stored OAuth tokens resident on the local machine.
And the most prolific tool for stealing it, until law enforcement hit it in 2025, was a piece of malware called Lumma. Lumma (also known as LummaC2) isn't a single cybercrime gang—it is a commercial product.
A recent campaign, active at least since December 2024, is promoting LummaStealer disguised as cracked software... Upon extraction the final payload is a LummaStealer executable.
Additional tradecraft and techniques: Usage of open-source tooling: ScreenConnect, FleetDeck, AnyDesk, RustDesk, Splashtop, Pulseway, TightVNC, LummaC2, Level.io, Mesh, TacticalRMM, Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware... Thousands of repositories are masquerading as AI skills or MCP servers... By copying code, creating convincing README files, and impersonating developer identities, the fake repositories are very closely resembling legitimate open-source projects.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
PowerShell (-nop, -ep bypass) used across XWorm, DonutLoader, and Lumma ClickFix chains for staged payload decryption and execution
The suspicious pattern is MSBuild starting from a newly extracted game-installer directory, reading unexpected project files, loading code from a user-writable path, and then making network connections or spawning later stages. MITRE tracks this type of abuse as Trusted Developer Utilities Proxy Execution: MSBuild.
Victims were prompted to retrieve ProFluxeFlowAi-win-Setup.exe from a GitHub repository named shippingtechnologymovie in the AI-techVideos path.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
one which delivers Lumma Stealer via files disguised as 1080p WEBRip and Blu-ray releases of The Odyssey
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
The suspicious pattern is MSBuild starting from a newly extracted game-installer directory, reading unexpected project files, loading code from a user-writable path, and then making network connections or spawning later stages. MITRE tracks this type of abuse as Trusted Developer Utilities Proxy Execution: MSBuild.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
If the suspicious installer ran, assume browser-saved passwords, cookies, authentication tokens, Discord or gaming sessions, and wallet data may have been exposed.
If the suspicious installer ran, assume browser-saved passwords, cookies, authentication tokens, Discord or gaming sessions, and wallet data may have been exposed.
Техники Credentials from Web Browsers (T1555.003) и Steal Web Session Cookie (T1539) по MITRE ATT&CK описывают этот вектор. Инфостилеры - Lumma (LummaC2), StealC, Vidar, Rhadamanthys и другие ... вытаскивают из браузера сохранённые пароли...
Il est principalement conçu pour collecter des informations sensibles sur les systèmes compromis, telles que des identifiants, des données de navigation, des portefeuilles de cryptomonnaies et d’autres informations confidentielles.
1,493 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer referenced in separate but contemporaneous campaigns, including one delivered through fake movie files and another via cracked software and pirated game lures.
Referenced as a Russian-cybercrime-associated infostealer sharing certificate signer overlap; not part of the main malware focus.
Referenced as another infostealer delivered alongside Remus in shared distribution infrastructure; also cited in 'Lumma-style browser key theft' comparison.
An information stealer observed as a possible final payload in some RenPy Loader chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.