Lumma Stealer, also tracked as LummaC2 or LummaC, is a Windows information-stealing malware family written in C++ and active since at least 2022. It is widely operated under a malware-as-a-service model and has become one of the most broadly deployed commodity stealers in the cybercrime ecosystem. The malware is designed to harvest sensitive data from compromised systems, including browser-stored credentials, cookies, session tokens, autofill data, and cryptocurrency wallet information. Reporting also associates Lumma with large-scale credential theft that has subsequently been used to support follow-on criminal activity and, in some cases, cyber-espionage operations.
Lumma is frequently distributed through social-engineering and malware-delivery ecosystems rather than through self-contained exploitation. Observed delivery vectors include ClickFix lures that trick users into pasting and executing malicious commands, malvertising, fake cracked-software downloads, SEO-poisoned pages promoting pirated software or keygens, and drive-by delivery through third-party loaders. It has also been linked to broader MaaS and loader infrastructures such as Factory-v3 and Dolphin Loader, indicating use by multiple affiliates and operators.
On infected hosts, Lumma focuses on credential and session theft from browsers and related applications. It is commonly discussed alongside stealer-log markets because stolen data is packaged and monetized at scale. The family is actively maintained, with frequent updates intended to evade browser protections and defensive tooling. Observed campaigns and sandboxed samples also show supporting behaviors such as persistence, system and software discovery, and process injection or tampering. In some delivery chains, Lumma has been deployed through masqueraded installers and remote-management abuse.
Lumma has been prominent enough to attract coordinated law-enforcement disruption and sanctions activity. Public reporting states that international action against LummaC2 infrastructure began in 2025, and later sanctions targeted developers and operators linked to the service. Government statements have further asserted that credentials stolen via Lumma were used by Russian state actors to support espionage against global targets. Victimology spans consumers, enterprises, and small and medium-sized businesses, with broad global distribution and especially heavy impact on Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-1731 BeyondTrust RS/PRA 9.8 Yes (GitHub) Yes (BT26-02) ... CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments.
31 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An employee at Context.ai downloaded compromised scripts containing Lumma Stealer malware, which harvested corporate credentials, active browser session cookies, and stored OAuth tokens resident on the local machine.
And the most prolific tool for stealing it, until law enforcement hit it in 2025, was a piece of malware called Lumma. Lumma (also known as LummaC2) isn't a single cybercrime gang—it is a commercial product.
A recent campaign, active at least since December 2024, is promoting LummaStealer disguised as cracked software... Upon extraction the final payload is a LummaStealer executable.
Additional tradecraft and techniques: Usage of open-source tooling: ScreenConnect, FleetDeck, AnyDesk, RustDesk, Splashtop, Pulseway, TightVNC, LummaC2, Level.io, Mesh, TacticalRMM, Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
Among these threats, Lumma Stealer has emerged as a particularly sophisticated player since its introduction in 2022 by the threat actor known as Lumma. Initially marketed as LummaC2, this information stealer quickly gained traction in underground forums, with prices starting at $250.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
A single set of stolen corporate credentials gets sold to an initial access broker, who sells access to a ransomware affiliate, who deploys within days.
Typical attacks require them to copy and paste a command, often PowerShell, into their system, where the malicious activity really begins.
RUYP decrypts to "WScript.Shell" and is used to create an ActiveXObject that will execute the decrypted payload residing in YqlKx
Command and Scripting Interpreter: AutoIT ... AutoHotKey & AutoIT T1059.010 ... pid Process 6088 AutoIt3.exe
A single set of stolen corporate credentials gets sold to an initial access broker, who sells access to a ransomware affiliate, who deploys within days.
Event Triggered Execution: Installer Packages ... Installer Packages T1546.016
Adds Run key to start application ... Registry Run Keys / Startup Folder T1547.001 ... Set value \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\Endpoint Manager = "C:\Program Files (x86)\COMODO\Endpoint Manager\ITSMAgent.exe"
A single set of stolen corporate credentials gets sold to an initial access broker, who sells access to a ransomware affiliate, who deploys within days.
Event Triggered Execution: Installer Packages ... Installer Packages T1546.016
Adds Run key to start application ... Registry Run Keys / Startup Folder T1547.001 ... Set value \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\Endpoint Manager = "C:\Program Files (x86)\COMODO\Endpoint Manager\ITSMAgent.exe"
Obfuscation de chaînes identique : encodage unique par chaîne, décodage octet par octet à l’exécution... Obfuscation du flux de contrôle similaire...
A single set of stolen corporate credentials gets sold to an initial access broker, who sells access to a ransomware affiliate, who deploys within days.
The UK sanctions also target individuals linked to Lumma Stealer, an information-stealing malware used to steal credentials and other sensitive data from compromised devices. The UK government said Russia has used credentials obtained through Lumma Stealer to support cyber espionage operations.
The sanctions are also aimed at individuals behind Lumma Stealer for enabling cybercriminals to collect sensitive information from compromised devices at scale. Russia is said to have used the stealer's stolen credentials to conduct cyber espionage operations against targets globally.
Collecte de credentials, cookies, tokens de session, données autofill sur tous les navigateurs Chromium et Firefox
The UK is also sanctioning individuals behind Lumma Stealer which enables cybercriminals to collect sensitive information from compromised devices at scale. The UK can reveal that Russia has used Lumma Stealer’s stolen credentials to conduct cyber espionage operations against targets globally
Enumerates connected drives ... Query Registry T1012 ... Checks installed software on the system ... Query Registry T1012 ... Checks SCSI registry key(s) ... Query Registry T1012
Enumerates connected drives ... System Information Discovery T1082 ... Enumerates physical storage devices ... System Information Discovery T1082 ... Checks processor information in registry ... System Information Discovery T1082
Enumerates connected drives ... Peripheral Device Discovery T1120 ... Checks SCSI registry key(s) ... Peripheral Device Discovery T1120
1,280 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer observé comme payload fréquent dans les campagnes ClickFix.
An information-stealing malware family described as the most prolific payload delivered through ClickFix campaigns.
An infostealer Malware-as-a-Service platform used to steal sensitive data, browser credentials, crypto wallets, and system information.
An infostealer active in June 2026 distribution campaigns, delivered via executable files and DLL side-loading, often under the guise of illegal software.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.