Lumma Stealer is a prolific criminal information-stealing malware operation run as a malware-as-a-service offering. It has been one of the most prevalent infostealer threats observed in 2025 and has infected large numbers of Windows systems worldwide. The operation is associated with aliases including LummaStealer, Lumma Stealer Group, Lumma Stealer Operators, and Lumma Stealer Team. Its primary purpose is theft of credentials and other sensitive user data, including cryptocurrency wallet data, with stolen access and logs supporting downstream cybercrime ecosystems such as initial access brokerage and ransomware intrusion chains. Lumma Stealer has been marketed commercially to other criminals on a subscription basis, reflecting an organized service model with ongoing operator support. Recent campaigns have relied heavily on social engineering rather than vulnerability exploitation. A prominent delivery pattern uses ClickFix-style lures, including fake CAPTCHA or website-fix prompts that trick victims into manually executing malicious commands. Distribution has also been tied to pirated media, cracked software, adult-content lures, fake Telegram channels, gaming-mod themes, and other deceptive channels designed to induce user execution. CastleLoader has been used as a core delivery component in many campaigns, enabling flexible payload delivery and rapid infrastructure changes. The operation demonstrates strong defense-evasion and operational resilience. Following coordinated law-enforcement disruption in 2025, Lumma Stealer operators rapidly migrated infrastructure, adopted alternative loaders and delivery techniques, and resumed activity through more discreet channels. Reported evasion and execution techniques associated with Lumma Stealer include DLL sideloading and overlay injection, alongside stealthier delivery tradecraft intended to bypass controls focused on malicious downloads. Lumma Stealer is best characterized as a financially motivated cybercriminal operation centered on credential theft, data exfiltration, and scalable initial access generation rather than espionage or destructive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operators behind the LummaStealer malware-as-a-service (MaaS) infostealer are resurging post-2025 disruption, shifting toward social-engineering-heavy infection chains (notably fake CAPTCHA ‘ClickFix’ prompts that induce users to copy/paste malicious commands) and leveraging CastleLoader as a flexible delivery mechanism to swap payloads and C2 infrastructure to evade detection.
Information stealer targeting credentials and cryptocurrency wallets, using browser fingerprinting and secondary payloads, with high-volume infections via diverse delivery methods.
Operators of Lumma Stealer provided malware-as-a-service, infecting hundreds of thousands of Windows computers globally to steal information.
Operators of Lumma Stealer are responsible for the majority of infostealer infections observed, targeting credentials and session tokens to facilitate further compromise or sale of access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.