The U.S. Department of Justice said it seized domains tied to a major information-stealing malware operation involving Lumma Stealer, disrupting command-and-control infrastructure and associated marketplaces. Trend Micro and TrendAI reported that the malware-as-a-service operation suffered a short-lived drop in activity after roughly 2,300 malicious domains were taken down, but victim-account targeting recovered within weeks and returned to typical levels by June and July 2025.
Researchers said Lumma operators quickly adapted by moving infrastructure away from heavy Cloudflare reliance to other providers, including Russia-based Selectel, and by expanding covert delivery methods. Campaigns distributing Lumma used AI-assisted fake GitHub repositories, fake crack and keygen sites, ClickFix fake CAPTCHA lures, and social media promotion to push loaders such as SmartLoader and the stealer itself. TrendAI also cited a developer claim that authorities accessed and wiped servers through a suspected iDRAC vulnerability before the operators restored access and disabled the exposed remote-management interface.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Trend Micro observed the number of accounts targeted by Lumma Stealer steadily returning to typical levels from June through July 2025, indicating a rapid operational recovery.
After the takedown, Lumma operators reduced their heavy use of Cloudflare and diversified to other providers. Trend Micro observed Lumma domains using Russia-based provider Selectel, especially in June 2025 shortly after the disruption.
On the XSS underground forum, a primary Lumma developer said nearly 2,500 Lumma-related domains had been seized. The developer also alleged authorities exploited a suspected IDRAC vulnerability, formatted disks and backups twice, and replaced the control panel with a phishing page.
Trend Micro observed a slight decline in the number of unique accounts targeted by Lumma malware during May 2025 following the law enforcement action.
A global law enforcement operation in May 2025 seized or blocked about 2,300 malicious domains tied to Lumma Stealer, including five domains used as administrator and customer login panels. The action disrupted Lumma's command-and-control infrastructure and marketplaces and severed infected machines from Lumma servers.
Trend Micro published research describing threat actors using fake GitHub repositories with AI-generated README files to distribute LummaStealer and SmartLoader.
Trend Micro described Lumma Stealer as a prolific information-stealing malware-as-a-service operation active since late 2022.
After the takedown, the Lumma team claimed it regained access to its servers and disabled the vulnerable remote-management interface. Trend Micro said infrastructure activity began increasing again within weeks of the disruption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcejustice.gov
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.