Lumma Stealer, also widely known as LummaC2, is a subscription-based malware-as-a-service infostealer active since 2022. It is one of the most prevalent commodity stealers in recent cybercrime operations and has been repeatedly associated with large-scale credential theft, browser data harvesting, and the resale of stolen access for follow-on intrusion activity. The malware is used to collect usernames, passwords, browser cookies, session data, cryptocurrency wallet information, and other sensitive data from compromised Windows systems, making it valuable both for direct monetization and as an initial-access source for other threat actors.
Lumma is commonly distributed through social-engineering-heavy delivery chains rather than bespoke exploitation. Observed infection vectors include fake CAPTCHA and ClickFix lures, trojanized GitHub repositories, fake browser updates, cracked-software and keygen themes, malicious downloads promoted through YouTube or SEO poisoning, compromised websites, and malicious LNK-based delivery. It has also been delivered by intermediary malware such as RenPy Loader and has appeared in campaigns using fast-flux-style infrastructure and blockchain-based infrastructure-hiding techniques.
Once executed, Lumma focuses on theft and exfiltration of user data from browsers and related applications. Its output is frequently traded in criminal markets and used by initial access brokers and intrusion operators. Stolen Lumma logs have been linked to breaches of cloud and file-sharing environments, including cases where harvested credentials and session artifacts were used to access enterprise services without exploiting software vulnerabilities. This places Lumma within a broader cybercrime supply chain in which infostealer infections are rapidly converted into account compromise, data theft, and extortion opportunities.
Lumma has been tied in reporting to multiple criminal ecosystems and infrastructure providers, including sanctions-related actions against individuals and entities accused of supporting its development, sale, or hosting. It has also been associated with the threat actor tracked as Water Kurita in earlier distribution activity, and it has remained prominent even after law-enforcement disruption efforts targeting related infrastructure. Its continued prevalence across ClickFix, fake software, and repository-based campaigns underscores its role as a durable and highly commoditized infostealer in the contemporary threat landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-1731 BeyondTrust RS/PRA 9.8 Yes (GitHub) Yes (BT26-02) ... CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments.
31 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It is believed that FakeGit is an evolution of a previous malware operation that was previously associated with Water Kurita and that used Lumma Stealer.
An employee at Context.ai downloaded compromised scripts containing Lumma Stealer malware, which harvested corporate credentials, active browser session cookies, and stored OAuth tokens resident on the local machine.
And the most prolific tool for stealing it, until law enforcement hit it in 2025, was a piece of malware called Lumma. Lumma (also known as LummaC2) isn't a single cybercrime gang—it is a commercial product.
A recent campaign, active at least since December 2024, is promoting LummaStealer disguised as cracked software... Upon extraction the final payload is a LummaStealer executable.
Additional tradecraft and techniques: Usage of open-source tooling: ScreenConnect, FleetDeck, AnyDesk, RustDesk, Splashtop, Pulseway, TightVNC, LummaC2, Level.io, Mesh, TacticalRMM, Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Operators distribute malware through pirated software repositories, malvertising networks, and compromised websites with the goal of infecting as many machines as possible.
There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware... Thousands of repositories are masquerading as AI skills or MCP servers... By copying code, creating convincing README files, and impersonating developer identities, the fake repositories are very closely resembling legitimate open-source projects.
PowerShell (-nop, -ep bypass) used across XWorm, DonutLoader, and Lumma ClickFix chains for staged payload decryption and execution
Infection : A user, usually on a personal or unmanaged device, executes the stealer payload through a low-effort but high-volume lure.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
Более 800 из них маскировались под навыки для ИИ-агентов и MCP-серверы... использовали имена настоящих разработчиков, накручивали звезды и форки, создавали правдоподобные README-файлы и копировали описания популярных инструментов.
Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens harvested from infected endpoints, then replaying those sessions directly against cloud consoles, SaaS platforms, and VPN gateways.
The UK sanctions also target individuals linked to Lumma Stealer, an information-stealing malware used to steal credentials and other sensitive data from compromised devices. The UK government said Russia has used credentials obtained through Lumma Stealer to support cyber espionage operations.
Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both observed across current stealer families.
The sanctions are also aimed at individuals behind Lumma Stealer for enabling cybercriminals to collect sensitive information from compromised devices at scale. Russia is said to have used the stealer's stolen credentials to conduct cyber espionage operations against targets globally.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, covering theft of saved browser passwords, cookies, and autofill data.
LummaC2 is a Malware-as-a-Service platform used to steal sensitive data, browser credentials, crypto wallets, and system information.
1,298 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Subscription-based malware-as-a-service infostealer delivered through fake CAPTCHA ClickFix pages, trojanized GitHub repositories, and malicious YouTube-linked downloads.
Malware referred to here as a botnet and cited as hacking software used in numerous cybercrime activities in Europe.
A market-leading infostealer sold as malware-as-a-service that steals passwords, cookies, crypto wallets, and session data. In the report it is highlighted as a major source of stealer logs used for cloud-account compromise and is commonly paired with CastleLoader in ClickFix infection chains.
Infostealer referenced as part of an earlier related campaign that researchers believe FakeGit continues.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.