Rival cybercriminals launched a doxxing campaign against the alleged operators of Lumma Stealer, a prominent Malware-as-a-Service platform used to steal credentials, financial data, and crypto wallets. Sensitive personal and operational details of five individuals associated with Lumma Stealer were published online, including passport numbers and financial records, following a failed law enforcement takedown attempt earlier in the year. The campaign, which intensified between late August and early October 2025, also resulted in the compromise of the group’s official Telegram accounts, severely disrupting their communications and operations.
This exposure led to a significant drop in Lumma Stealer’s activity, creating a vacuum in the infostealer market. As Lumma Stealer’s presence waned, threat actors began adopting alternatives such as Vidar Stealer 2.0, which was released with enhanced capabilities and a complete code rewrite. The shift in the cybercriminal ecosystem highlights how internal rivalries and operational disruptions can rapidly alter the landscape of malware distribution and adoption.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Hackread published a report stating that rival hackers had doxed alleged operators of the Lumma Stealer malware. The reference marks a public disclosure of claimed attribution-related information about the operators.
Trend Micro released research describing 'Vidar Stealer 2.0' and its upgraded infostealer capabilities. The reference indicates public disclosure of technical details about the malware's speed, breadth, and evasiveness.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.