Lumma Stealer continued to expand as a prolific malware-as-a-service infostealer, with researchers reporting sharp growth in detections and increasingly diverse delivery chains. Microsoft attributed the malware and its command-and-control ecosystem to Storm-2477, which operates Lumma for affiliates that build payloads and run campaigns through a management panel. ESET reported Lumma detections surged 369% in late 2024, while additional reporting from Netskope and other researchers highlighted ongoing fake CAPTCHA/ClickFix lures and fresh payload variants designed to evade detection.
Observed campaigns used multiple infection paths, including phishing, malvertising, compromised websites, trojanized software, abuse of trusted platforms such as GitHub, and delivery by other malware including DanaBot. Microsoft described an early-April campaign that combined EtherHiding hosted through Binance Smart Chain smart contracts with ClickFix social engineering, and an April 7 campaign targeting Canadian organizations that used Prometheus TDS redirection plus mshta and PowerShell stages to deploy Lumma alongside Xworm. The malware was reported stealing credentials and cryptocurrency wallets, using process injection and hollowing, and relying on layered infrastructure with hardcoded domains and fallback channels through Steam and Telegram behind Cloudflare; Microsoft said its disruption effort led to the takedown, suspension, or blocking of about 2,300 malicious domains tied to Lumma operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
A Malware-Traffic-Analysis.net entry dated August 10, 2026 published analysis artifacts for Lumma Stealer or a variant, including notes, a PCAP, and a malware archive. The post noted that the ZIP files were password-protected under a new site password scheme.
On May 21, 2025, Microsoft said its Digital Crimes Unit facilitated a disruption of Lumma infrastructure. The action resulted in the takedown, suspension, or blocking of about 2,300 malicious domains supporting the malware’s ecosystem.
On April 7, 2025, Microsoft observed a campaign sending thousands of invoice-themed emails to organizations in Canada. The attack used Prometheus TDS and ClickFix redirection to execute mshta, PowerShell stages, and ultimately deploy Lumma Stealer bundled with Xworm.
In early April 2025, Microsoft observed compromised websites using EtherHiding and ClickFix techniques to deliver Lumma Stealer. The campaign used injected JavaScript to retrieve code via Binance Smart Chain infrastructure and trick users into running an mshta command.
In November 2024, Kroll described a social-engineering campaign in which victims searching for tools such as YouTube-to-MP3 converters were redirected to fake human-verification pages that copied malicious PowerShell into the Windows Run dialog to install Lumma Stealer. Kroll also published technical details including persistence via the CurrentVersion\Run registry key, hardcoded .shop C2 domains, URLs, and file hashes, and said its SOC remediated multiple incidents before follow-on attacker actions succeeded.
In October 2024, CERT-AGID observed a Lumma Stealer campaign that lured victims with a fake GitHub security warning and a bogus CAPTCHA page instructing Windows users to run a malicious PowerShell command. CERT-AGID later analyzed a compromised Italian WordPress site delivering the same chain, notified the site operators, and shared related indicators of compromise through its IoC feed.
In October 2024, international authorities including the Dutch National Police, the FBI, and Europol took down RedLine Stealer and META Stealer during Operation Magnus. The action included arrests, infrastructure disruption, and seizure of a database of criminal clients.
On 2024-03-07, Malware-Traffic-Analysis.net published an infection analysis showing Latrodectus leading to Lumma Stealer. The post released supporting artifacts including IOCs, a malspam sample, packet captures, and malware archives tied to the activity.
ESET reported that Lumma Stealer detections increased by 369% in H2 2024, with nearly 50,000 detections, and that the malware entered ESET’s top 10 infostealers for the first time. ESET also said Lumma accounted for roughly three fourths of its H2 2024 cryptostealer detections and was spread through fake CAPTCHA pages, GitHub lures, pirated software, and injector campaigns.
On 2023-02-06, a Korean voice actor YouTuber was targeted with a spear-phishing email impersonating Bandai Namco that delivered a Dropbox ZIP containing a malicious file. Executing it led to Pure Crypter loading Lumma Stealer, after which the victim’s YouTube account was compromised and renamed to a Tesla-themed channel.
On January 6, 2023, Cyble reported on LummaC2 as an information-stealing malware sold via a Russian-language website with pricing tiers from $250 to $20,000 and supported through Telegram channels. The report detailed its theft of browser, wallet, and local file data and identified active command-and-control servers at 195.123.226.91 and 144.76.173.247.
In a November 2023 interview, a Lumma representative said the Lumma project started on 2022-12-21. The same interview described the stealer as having roughly 400 active customers and ongoing product development.
The reference states that Lumma Stealer was first observed around August 2022, marking the emergence of the malware family later known as LummaC2 or Lummac. It subsequently developed into a prominent malware-as-a-service infostealer.
Bitdefender identified a campaign using fake pirated downloads of the film "The Odyssey" to distribute Lumma Stealer. The malware was disguised as Windows executables made to look like video files using VLC icons and hidden file extensions, prioritizing rapid theft of credentials, cookies, payment data, and cryptocurrency wallet information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemalware-traffic-analysis.net
Open sourcemedium.com
Open sourcecertego.net
Open sourceg0njxa.medium.com
Open sourcemedium.com
Open sourceblog.cyble.com
Open sourceweb-assets.esetstatic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.