Lumma Stealer, also known as LummaC2, is a Windows information-stealing malware family operated as a cybercrime service and tracked by Trend Micro as Water Kurita. It collects browser-resident data, including saved passwords, authentication cookies, session artifacts, and credentials associated with locally installed applications. Theft of active browser sessions enables downstream account takeover through replay of authenticated cookies, potentially bypassing password and login-time MFA or SSO checks. Lumma has been associated with theft of Claude sessions and credentials, as well as a 2026 third-party compromise chain in which stolen corporate credentials, session tokens, and OAuth tokens enabled access to cloud and enterprise environments.
Lumma is distributed through malicious applications and unofficial downloads, including cracked software, and has been delivered through Google-hosted social-engineering content, fake CAPTCHA/ClickFix campaigns, phishing, URL redirection, malvertising, and SEO poisoning. Observed delivery chains use obfuscated payloads and multistage loaders. Campaigns have targeted organizations worldwide as well as individual users. Law-enforcement action in 2025 disrupted the Lumma ecosystem, although subsequent activity indicated that the operation restored infrastructure before a later decline in observed activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-1731 BeyondTrust RS/PRA 9.8 Yes (GitHub) Yes (BT26-02) ... CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments.
39 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Following the sweeping law enforcement operation against Lumma Stealer in early 2025... recent monitoring of Lumma Stealer reveals a steady and quiet resurgence in its activity.
Recently, Hudson Rock analyzed a unique infection from a LummaC2 infostealer log. The victim wasn’t a corporate employee or an unsuspecting consumer. The victim was a high-level North Korean threat actor operating a sophisticated malware development rig.
In this previous campaign, the bitbucket folder contained additional malwares such as Remcos, Sectop RAT, Lumma Stealer, Mars Stealer, and Darktrack RAT.
Storm-2477 [[URL_981dc176_51]] Gruppe in Entwicklung Lumma Dieb
Lumma Stealer, also recognized as LummaC2, Lummac, or simply Lumma, stands as one of the most prominent and rapidly evolving information stealer threats within the global cybersecurity landscape.
The gang uses code-signing for multiple components of their campaign... information stealing malware, like Lumma infostealer
19 distinct techniques documented for this family, organized by ATT&CK tactic.
A bad actor was “using those login sessions to access Claude accounts and consume their usage.”
Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves.
The campaign uses Google Groups, Google Docs, and Google Drive to embed deceptive download links within legitimate-looking discussions.
The script then uses Microsoft HTML Application Host (mshta) or base64-encoded PowerShell to execute a highly obfuscated command, which, in turn, connects to another site and executes multistage encoded scripts directly to the memory.
The campaign dynamically redirects victims based on operating system, delivering an oversized, obfuscated Lumma payload to Windows users.
The operation leverages more than 4,000 malicious Google Groups and 3,500 Google-hosted URLs to embed deceptive download links within legitimate-looking discussions.
A bad actor was “using those login sessions to access Claude accounts and consume their usage.”
Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves.
« Ces programmes copient les cookies de connexion stockés dans le navigateur » ; « Un attaquant qui copie ce cookie et le rejoue depuis un autre appareil apparaît alors [...] comme la personne ayant déjà réussi cette vérification ».
1,694 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Voleur d’informations utilisé pour copier les cookies de session stockés dans les navigateurs ainsi que les mots de passe enregistrés, permettant le détournement de sessions et le contournement de l’authentification à deux facteurs.
Named as one of several infostealers identified on impacted systems that can collect login cookies, application credentials, and browser passwords, enabling theft of active Claude sessions.
An information stealer identified as capable of stealing active Claude session cookies from infected Windows computers, enabling account access without passwords and bypassing MFA and SSO.
Infostealer used to steal Claude login sessions from affected Windows computers, enabling unauthorized account access and consumption of available tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.