Water Kurita is Trend Micro's designation for the cybercriminal operation behind Lumma Stealer, also known as LummaC2 and LummaC2 Stealer. The operation has offered the malware as an information-stealer-as-a-service since at least 2022, providing customers with infrastructure and tooling used to steal sensitive data from compromised endpoints. It is also tracked as Storm-2477. Lumma Stealer has been distributed through fake software cracks and key generators, search-engine manipulation and malvertising, compromised websites using ClickFix-style fake CAPTCHA lures, malicious GitHub repositories, and social-media campaigns promoting fraudulent software downloads. ClickFix chains have induced victims to execute PowerShell commands that decrypt and run payloads in memory. The operation has used process injection into legitimate browser processes to blend malicious traffic with browser activity and evade security controls. The malware's command-and-control functionality has incorporated detailed browser and host fingerprinting, including WebGL, canvas, audio, WebRTC, device, display, font, plugin, and network characteristics. This capability can assist operators in identifying analysis environments and tailoring payload deployment. Lumma Stealer has also deployed GhostSocks as a secondary payload. International law-enforcement action in May 2025 disrupted Lumma-related command-and-control infrastructure, but the operation restored activity within weeks and diversified its hosting arrangements. A later doxxing campaign and compromise of its communications channels coincided with a substantial decline in activity during September 2025, followed by renewed activity from October 2025. The operation's apparent role as a malware-as-a-service provider and associated commercial activity indicate a primarily financially motivated criminal enterprise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealer malware operation experiencing a sharp decline in C2 activity, sample detections, and targeted endpoints after a doxxing/exposure campaign and compromise of its Telegram accounts disrupted operators and customer communications.
Operators/developers behind Lumma Stealer who rapidly rebuilt infrastructure and resumed campaigns after the 2025 law-enforcement takedown, using delivery methods including fake cracks/keygens, ClickFix fake CAPTCHA lures, GitHub-hosted malware, and social-media-driven distribution.
Referenced as the actor previously linked to an earlier Lumma stealer distribution campaign that researchers believe FakeGit may continue.
Referenced as the threat actor previously associated with an earlier malware operation that FakeGit is believed to have evolved from; the current campaign uses counterfeit GitHub repositories masquerading as AI tools and MCP servers to distribute malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.