Water Kurita is a cybercriminal threat actor designation used for activity associated with the Lumma Stealer malware-as-a-service ecosystem, also referred to in reporting as Storm-2477. The actor has been linked to large-scale information-stealing operations and malware distribution campaigns centered on credential and data theft from compromised endpoints. Water Kurita is associated with Lumma Stealer, a prominent infostealer offered through criminal channels since at least 2022, and with follow-on activity believed to have evolved into the FakeGit campaign. In that later activity, operators used thousands of counterfeit code repositories and fake developer personas to impersonate legitimate open-source projects, including AI-related tools, skills, agents, workflows, and Model Context Protocol servers. These lures directed victims to download archive files that launched a Lua-based loader chain, installed SmartLoader, established persistence through scheduled tasks, retrieved command-and-control information via a blockchain smart contract, downloaded additional encrypted stages from code-hosting services, and ultimately delivered the StealC infostealer. The actor’s tradecraft demonstrates strong use of social engineering and trust abuse in developer and open-source ecosystems. Observed techniques include cloning legitimate projects, fabricating repository metadata and documentation, impersonating developers, and leveraging AI-assisted software discovery to increase exposure of malicious lures. This reflects an emphasis on initial access through deceptive software distribution, followed by persistence, payload retrieval, and credential and information theft. Water Kurita’s activity is financially motivated and aligned with the broader infostealer and malware-as-a-service underground economy. Reporting also indicates that disruption to the Lumma Stealer operation in 2025, including a doxxing campaign against alleged core members and compromise of communication channels, coincided with a sharp decline in observable Lumma activity and customer migration to competing infostealers such as Vidar and StealC.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the actor previously linked to an earlier Lumma stealer distribution campaign that researchers believe FakeGit may continue.
Referenced as the threat actor previously associated with an earlier malware operation that FakeGit is believed to have evolved from; the current campaign uses counterfeit GitHub repositories masquerading as AI tools and MCP servers to distribute malware.
Attributed by Trend Micro to an older malware distribution operation using Lumma Stealer that is described here as a precursor or continuation context for the FakeGit campaign.
Threat actor label used by Trend Micro for activity involving Lumma Stealer; observed evolving C2 tradecraft to include browser fingerprinting and stealthy JavaScript-based data collection/exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.