Skip to main content
Mallory
Financially Motivated1 malware family

Water Kurita

Also known aswater_kurita

Water Kurita is a tracking name for the Lumma Stealer cybercriminal operation, also tracked as Storm-2477. Lumma Stealer, also known as LummaC2 Stealer and LummaC2, has been offered as a malware-as-a-service infostealer on underground forums since at least August 2022 and was described as one of the most prominent information stealers in the reporting period. Trend Micro reported that the group’s activity declined sharply following an underground doxxing campaign targeting alleged core members, after previously resuming operations on rebuilt infrastructure about two months after a May law-enforcement disruption. The doxxing campaign allegedly exposed five supposed core members and was assessed by Trend Micro as likely involving insider knowledge or access to compromised accounts or databases; however, Trend Micro cautioned that the identities and involvement of the named individuals were not independently verified. Reported impacts included compromise of the group’s Telegram account, disrupting communications with customers. Trend Micro also reported that Lumma Stealer used browser fingerprinting as part of its command-and-control tactics. The decline in Lumma activity reportedly pushed some criminals toward alternative infostealers such as Vidar and StealC and affected the Amadey pay-per-install ecosystem used to distribute Lumma. No nation-state attribution is stated in the provided content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.