Lumma Stealer, also tracked as LummaC2, Lumma, and LummaC, is a Windows-focused information-stealing malware family written in C++ and active since at least 2022. It operates under a malware-as-a-service model and became one of the most widely deployed infostealers globally during 2024 and 2025, with frequent updates aimed at evading browser protections and endpoint detection. The malware is used to harvest sensitive data from compromised systems at scale, including browser-stored credentials, session cookies, authentication tokens, autofill data, cryptocurrency wallet information, and other locally accessible secrets. Stolen credentials obtained through Lumma infections have also been used to support follow-on cyberespionage activity.
Lumma is commonly distributed through social-engineering-driven delivery chains, especially ClickFix lures that trick users into manually executing malicious PowerShell or similar commands under the guise of fixing an error, completing verification, or installing software. It has also been observed in fake software download and trojanized installer campaigns, including abuse of remote monitoring and management tooling to stage payload execution. In broader infostealer ecosystems, Lumma infections are generally opportunistic and high-volume rather than narrowly pre-targeted, with victim selection and monetization often occurring after data theft.
On infected hosts, Lumma performs host reconnaissance and security-product checks, enumerates installed software and connected drives, and gathers system metadata such as language and processor details. Observed samples have established persistence through autorun mechanisms and shown process injection or process-tampering behavior. The malware communicates with command-and-control infrastructure to transmit stolen data and receive configuration. Reporting also links Lumma campaigns to session-theft recovery concerns because of its theft of browser cookies and active sessions.
Lumma has been repeatedly associated with the Russian-language cybercrime ecosystem and was significant enough to become the subject of coordinated international law-enforcement disruption and later sanctions actions targeting developers and operators. Public government statements have further asserted that credentials stolen via Lumma were used by Russia in support of cyberespionage operations against global targets. The malware has affected large numbers of victims, including thousands in the United Kingdom over a six-month period, and has been prominent in credential exposure affecting developer and AI-platform accounts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-1731 BeyondTrust RS/PRA 9.8 Yes (GitHub) Yes (BT26-02) ... CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments.
31 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An employee at Context.ai downloaded compromised scripts containing Lumma Stealer malware, which harvested corporate credentials, active browser session cookies, and stored OAuth tokens resident on the local machine.
And the most prolific tool for stealing it, until law enforcement hit it in 2025, was a piece of malware called Lumma. Lumma (also known as LummaC2) isn't a single cybercrime gang—it is a commercial product.
A recent campaign, active at least since December 2024, is promoting LummaStealer disguised as cracked software... Upon extraction the final payload is a LummaStealer executable.
Additional tradecraft and techniques: Usage of open-source tooling: ScreenConnect, FleetDeck, AnyDesk, RustDesk, Splashtop, Pulseway, TightVNC, LummaC2, Level.io, Mesh, TacticalRMM, Tailscale, Ngrok, WsTunnel, Rsocx, and Socat.
Groups like TA2727 use similar JavaScript injects and lures to distribute their own malware, including information stealers like Lumma and DeerStealer.
Among these threats, Lumma Stealer has emerged as a particularly sophisticated player since its introduction in 2022 by the threat actor known as Lumma. Initially marketed as LummaC2, this information stealer quickly gained traction in underground forums, with prices starting at $250.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
A single set of stolen corporate credentials gets sold to an initial access broker, who sells access to a ransomware affiliate, who deploys within days.
Operators distribute malware through pirated software repositories, malvertising networks, and compromised websites with the goal of infecting as many machines as possible.
Typical attacks require them to copy and paste a command, often PowerShell, into their system, where the malicious activity really begins.
RUYP decrypts to "WScript.Shell" and is used to create an ActiveXObject that will execute the decrypted payload residing in YqlKx
Command and Scripting Interpreter: AutoIT ... AutoHotKey & AutoIT T1059.010 ... pid Process 6088 AutoIt3.exe
A single set of stolen corporate credentials gets sold to an initial access broker, who sells access to a ransomware affiliate, who deploys within days.
Event Triggered Execution: Installer Packages ... Installer Packages T1546.016
although it copied itself in that folder for persistence
Adds Run key to start application ... Registry Run Keys / Startup Folder T1547.001 ... Set value \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\Endpoint Manager = "C:\Program Files (x86)\COMODO\Endpoint Manager\ITSMAgent.exe"
A single set of stolen corporate credentials gets sold to an initial access broker, who sells access to a ransomware affiliate, who deploys within days.
Event Triggered Execution: Installer Packages ... Installer Packages T1546.016
although it copied itself in that folder for persistence
Adds Run key to start application ... Registry Run Keys / Startup Folder T1547.001 ... Set value \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\Endpoint Manager = "C:\Program Files (x86)\COMODO\Endpoint Manager\ITSMAgent.exe"
Obfuscation de chaînes identique : encodage unique par chaîne, décodage octet par octet à l’exécution... Obfuscation du flux de contrôle similaire...
A single set of stolen corporate credentials gets sold to an initial access broker, who sells access to a ransomware affiliate, who deploys within days.
This malware is a dotnet dropper which is decoded and then invoked
The command, which is initially copied to the victim's clipboard is a Powershell command that uses Windows Common Information Model (CIM) to spawn a malicious mshta.exe process. The latter is used to parse and execute the code of an .hta file
The UK sanctions also target individuals linked to Lumma Stealer, an information-stealing malware used to steal credentials and other sensitive data from compromised devices. The UK government said Russia has used credentials obtained through Lumma Stealer to support cyber espionage operations.
The sanctions are also aimed at individuals behind Lumma Stealer for enabling cybercriminals to collect sensitive information from compromised devices at scale. Russia is said to have used the stealer's stolen credentials to conduct cyber espionage operations against targets globally.
They extract: Browser-saved credentials, autofill data Active session cookies (which bypass MFA entirely) Authentication tokens for GitHub, GitLab, AWS, Azure, and GCP
The UK is also sanctioning individuals behind Lumma Stealer which enables cybercriminals to collect sensitive information from compromised devices at scale. The UK can reveal that Russia has used Lumma Stealer’s stolen credentials to conduct cyber espionage operations against targets globally
Enumerates connected drives ... Query Registry T1012 ... Checks installed software on the system ... Query Registry T1012 ... Checks SCSI registry key(s) ... Query Registry T1012
Enumerates connected drives ... System Information Discovery T1082 ... Enumerates physical storage devices ... System Information Discovery T1082 ... Checks processor information in registry ... System Information Discovery T1082
Enumerates connected drives ... Peripheral Device Discovery T1120 ... Checks SCSI registry key(s) ... Peripheral Device Discovery T1120
1,272 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer Malware-as-a-Service platform used to steal sensitive data, browser credentials, crypto wallets, and system information.
An information stealer used to collect sensitive information from compromised devices at scale; the article says stolen credentials were used by Russia to support cyber espionage operations.
Lumma Stealer26
A prolific malware strain referenced in connection with sanctioned developers; no further technical detail is provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.