LummaStealer
LummaStealer is a prolific information-stealing malware operation run under a Malware-as-a-Service (MaaS) model, focused on stealing credentials (and reported alongside other infostealers as targeting cryptocurrency wallets). Reporting describes a resurgence in activity less than a year after a major 2025 law-enforcement disruption attempt, with operators demonstrating resilience by rapidly migrating to new hosting providers and adapting alternative loaders and delivery techniques. Recent LummaStealer infection growth is described as being driven primarily by social engineering rather than exploitation of technical vulnerabilities. A prominent tactic is “ClickFix,” which uses fake CAPTCHA prompts and similar lures (e.g., routine security checks or website “fixes”) to trick victims into copying and pasting malicious commands into a terminal, converting normal web interactions into direct command execution and helping bypass defenses that rely on detecting malicious file downloads. Many campaigns are reported to use CastleLoader as a core delivery mechanism to evade detection and to enable rapid swapping of payloads and command-and-control (C2) infrastructure. Defensive recommendations in the cited reporting emphasize user awareness (due to required user interaction), behavioral monitoring, and rapid response to credential compromise, noting the limitations of purely technical takedowns and signature-based detection against profitable credential-theft operations like LummaStealer.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operators behind the LummaStealer malware-as-a-service (MaaS) infostealer are resurging post-2025 disruption, shifting toward social-engineering-heavy infection chains (notably fake CAPTCHA ‘ClickFix’ prompts that induce users to copy/paste malicious commands) and leveraging CastleLoader as a flexible delivery mechanism to swap payloads and C2 infrastructure to evade detection.
Information stealer targeting credentials and cryptocurrency wallets, using browser fingerprinting and secondary payloads, with high-volume infections via diverse delivery methods.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.