Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory

LummaStealer

Also known asLummaStealer

LummaStealer is a prolific information-stealing malware operation run under a Malware-as-a-Service (MaaS) model, focused on stealing credentials (and reported alongside other infostealers as targeting cryptocurrency wallets). Reporting describes a resurgence in activity less than a year after a major 2025 law-enforcement disruption attempt, with operators demonstrating resilience by rapidly migrating to new hosting providers and adapting alternative loaders and delivery techniques. Recent LummaStealer infection growth is described as being driven primarily by social engineering rather than exploitation of technical vulnerabilities. A prominent tactic is “ClickFix,” which uses fake CAPTCHA prompts and similar lures (e.g., routine security checks or website “fixes”) to trick victims into copying and pasting malicious commands into a terminal, converting normal web interactions into direct command execution and helping bypass defenses that rely on detecting malicious file downloads. Many campaigns are reported to use CastleLoader as a core delivery mechanism to evade detection and to enable rapid swapping of payloads and command-and-control (C2) infrastructure. Defensive recommendations in the cited reporting emphasize user awareness (due to required user interaction), behavioral monitoring, and rapid response to credential compromise, noting the limitations of purely technical takedowns and signature-based detection against profitable credential-theft operations like LummaStealer.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.