Lumma Stealer, also known as LummaC2, is a Windows information-stealing malware family sold through a malware-as-a-service subscription model. It supports Windows 7 through Windows 11 and extracts sensitive data from multiple browsers, including stored credentials, session cookies, payment-card information, and browsing history. It also targets cryptocurrency wallets, browser extensions, and two-factor authentication-related data. Stolen information is exfiltrated to attacker-controlled infrastructure and traded through criminal marketplaces, enabling account takeover, financial theft, and subsequent intrusions into corporate systems.
Lumma is distributed through trojanized and cracked software, phishing links and attachments, fake browser updates, malicious advertising, and ClickFix social engineering. ClickFix campaigns use counterfeit CAPTCHA or troubleshooting prompts to persuade users to execute malicious commands through native Windows utilities. Observed infection chains have used WebDAV-hosted shortcuts, Microsoft Defender SmartScreen bypasses involving CVE-2024-21412, and browser exploitation involving CVE-2023-2033. Delivery chains employ obfuscated scripts, encrypted loaders, DLL sideloading through legitimate applications, and injection of the final payload into Windows processes.
Lumma affects both individual users and enterprise endpoints across multiple regions and industries, including manufacturing. Graceful Spider campaigns delivered Lumma alongside FlawedGrace, and Black Basta used Lumma as part of its initial-access operations. Its stolen logs became prominent in underground credential markets during 2023 and 2024. Law enforcement disrupted Lumma infrastructure in May 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Win32 TrueType font parsing is an old known exploit (CVE-2011-3402) abused by the attackers to elevate the necessary privileges for subsequent operations.
We have observed payloads containing exploits targeting JavaScript engine V8 (CVE-2023-2033) and a TrueType font parsing in Windows (CVE-2011-3402).
“When a user opens the internet shortcut file, it exploits CVE-2024-21412 to evade Microsoft Defender SmartScreen and triggers the execution of the LNK file hosted on the same WebDAV share.” The content also uses CVE-2024-21212 once for this same infection step; this appears to be a typographical error rather than a separate vulnerability.
이 취약점은 DarkGate 캠페인과 같은 실제 공격에서 악용되었다.
CVE-2026-1731 BeyondTrust RS/PRA 9.8 Yes (GitHub) Yes (BT26-02) ... CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments.
42 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These IOCs are associated with Truebot campaigns used by Graceful Spider to deliver FlawedGrace and LummaStealer payloads in May of 2023.
Employing the novel "ClickFix" technique impersonating IT tools, alongside more sophisticated tools including: LummaStealer, BerserkStealer and Custom Remote Access Trojans (RATs)
“The final payload that has been distributed at the time of research has been identified as Lumma stealer.”
Deployed information-stealing malware like “Lumma” and “StealC.”
The threat actor, tracked by Mandiant as UNC5587, used infostealer malware such as RedLine, Lumma, and Vidar to harvest credentials from infected employee devices.
Lumma Stealer activity resurged beginning the week of October 20, 2025, with new C&C browser-fingerprinting behavior. It injects from MicrosoftEdgeUpdate.exe into chrome.exe and contacts /api/set_agent endpoints to collect and exfiltrate browser and system fingerprints.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
1,778 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as an example of an information-stealing payload that users can be tricked into executing through ClickFix prompts and obfuscated PowerShell commands. The article provides no family-specific technical details.
Mentioned only as a comparison for Remus Stealer. The reference does not establish Lumma's participation in the analyzed campaign or describe its capabilities separately.
Mentioned only as background explaining customer distrust of malware-as-a-service stealers. The article supplies no technical details or operational relationship between Lumma and Warden.
Mentioned only as background in an interview about customers’ distrust of malware-as-a-service stealers. The content provides no technical details or operational connection between Lumma and Warden.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.