Lumma Stealer, also widely referred to as LummaC2 or Lumma, is a Windows information-stealing malware family first observed in 2022 and commonly sold and operated in cybercriminal ecosystems. It is primarily designed to harvest sensitive data from infected systems, including browser-stored credentials, cookies and other session material, cryptocurrency wallet data, and general host information. Multiple reporting streams also associate it with keylogging and broader data exfiltration functionality.
The malware is frequently delivered through socially engineered and crimeware-driven infection chains rather than as a standalone initial payload. Observed delivery mechanisms include fake browser update lures, ClickFix-style fake CAPTCHA or browser verification pages, phishing links, and cracked-software lures. Lumma has also appeared as a downstream payload in multi-stage loader chains involving malware such as HijackLoader, Latrodectus, PrivateLoader, SmokeLoader, and IDATLOADER, and has been linked to campaigns that also deployed other commodity malware families.
On execution, Lumma Stealer has been observed using several defense-evasion and execution techniques. Reported behaviors include process hollowing into legitimate Windows binaries, DLL side-loading through legitimate applications, hidden execution via .NET ProcessStartInfo with window suppression, abuse of mshta.exe to execute additional content, and security-software discovery using built-in commands to identify antivirus processes. In some campaigns, Lumma was embedded as an encrypted final-stage payload that was decrypted in memory and injected without being separately fetched to disk.
Operationally, Lumma is associated with financially motivated cybercrime activity and has been observed in campaigns tied to large-scale social-engineering operations and ransomware-adjacent ecosystems. It has been referenced alongside activity linked to Black Basta affiliates and in broad spam and lure-driven campaigns affecting enterprises and individual users. Its role is typically credential theft and collection of monetizable victim data for resale, account takeover, follow-on intrusion, or fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2026-1731 BeyondTrust RS/PRA 9.8 Yes (GitHub) Yes (BT26-02) ... CVE-2026-1731 (BeyondTrust) is associated with HAFNIUM and linked to Lumma Stealer, SparkRAT, and VShell malware deployments.
38 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this previous campaign, the bitbucket folder contained additional malwares such as Remcos, Sectop RAT, Lumma Stealer, Mars Stealer, and Darktrack RAT.
Storm-2477 [[URL_981dc176_51]] Gruppe in Entwicklung Lumma Dieb
Lumma Stealer, also recognized as LummaC2, Lummac, or simply Lumma, stands as one of the most prominent and rapidly evolving information stealer threats within the global cybersecurity landscape.
The gang uses code-signing for multiple components of their campaign... information stealing malware, like Lumma infostealer
2024-03-07 (THURSDAY): LATRODECTUS INFECTION LEADS TO LUMMA STEALER
Lumma Stealer, also recognized as LummaC2, Lummac, or simply Lumma, stands as one of the most prominent and rapidly evolving information stealer threats within the global cybersecurity landscape.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Over the past few years, cybercriminals have increasingly used the drive-by download technique to distribute malware via user web browsing.
It then starts a scheduled task named 'GoogleUpdateTaskMachineQC' ... (T1053: Scheduled Task/Job).
Una volta seguite le istruzioni fornite dal falso CAPTCHA, viene eseguito il seguente script PowerShell, il cui compito è quello di scaricare un file da una risorsa remota ed eseguirlo.
le vittime venivano avvisate di una presunta vulnerabilità di sicurezza nei loro repository GitHub e invitate a cliccare su un link sospetto. All’apertura del link, si trovavano di fronte a un falso CAPTCHA che le istruiva a copiare ed eseguire uno script PowerShell tramite la funzione WIN+R (Esegui).
The vulnerability is exploited by generating a URL file that can be activated using the following non-standard actions: 1. A single right-click (in all versions of Windows). 2. Deleting the file by using the delete button (only in Windows 10/11). 3. Dragging the file to another folder.
It then starts a scheduled task named 'GoogleUpdateTaskMachineQC' ... (T1053: Scheduled Task/Job).
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The final payload is not fetched from the network, nor is it dropped to disk in a separate file. Instead, it is embedded inside the config blob, appended past the module table.
Members frequently exchanged ideas on payload obfuscation... re-encrypt payloads... malware crypting, obfuscation, and evasion techniques...
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The blob carries its own key. The first xor_key_dwords * 4 bytes are the XOR key, and everything after is the encrypted PE. No length prefix, no wrapping header, just key dwords followed by ciphertext. The decryption is a dword-cycle XOR.
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
L’esecuzione dello script nelle sandbox online non ha prodotto risultati utili, poiché è in grado di rilevare la natura dell’ambiente, rendendo quindi necessaria un’analisi manuale.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
let threshold = 500; DeviceEvents | where ActionType == "GetAsyncKeyStateApiCall" | summarize count() by DeviceName, InitiatingProcessFileName, bin(Timestamp, 1h) | where count_ > threshold
“History” contained the Edge Browser history, “Login Data” contained the Edge Browser login data, “Cookies” contained the Edge browser cookies...
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
PrivateLoader begins by checking the system environment (T1082: System Information Discovery and T1012: Query Registry) to ensure it is suitable for the ensuing malware symphony.
“System.txt” contained the Lumma ID... and system information like the PC name, user, OS Version, HWID, Screen Resolution, Language, CPU Name, GPU, Physical Installed Memory.
L’esecuzione dello script nelle sandbox online non ha prodotto risultati utili, poiché è in grado di rilevare la natura dell’ambiente, rendendo quindi necessaria un’analisi manuale.
This was further corroborated by captured network traffic, reminiscent of Lumma. POST / HTTP / 1.1 ... Host : mastojh.cyou
1,638 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware mentioned only as an alias/association in Microsoft's threat actor naming table; no behavioral description is provided in the content.
An information-stealing malware sold as a malware-as-a-service that harvests browser passwords, session cookies, payment information, and cryptocurrency wallet details. In this campaign it is distributed via fake pirated movie downloads disguised as video files, with emphasis on immediate credential theft rather than persistence.
An information-stealing malware family; the content references Lumma Stealer or a variant in malware analysis notes.
Information-stealing malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.