Lumar, also known as PovertyStealer, is a Windows infostealer associated with cybercrime distribution operations and browser data theft. It has been observed alongside other commodity stealers in large-scale traffer activity and has been used in infections delivered through cracked-software lures and pay-per-install style distribution chains.
Its core role is theft of sensitive user data, particularly browser-resident secrets such as cookies and other Chrome-protected data. Lumar is among the stealer families reported to have adapted to Google Chrome’s App-Bound Encryption protections on Windows. Early iterations reportedly required administrator privileges to continue stealing Chrome data after that protection was introduced, but later versions implemented a bypass that worked with the privileges of the logged-in user. This places Lumar among the infostealers capable of continuing browser secret collection despite Chrome hardening measures.
The malware is relevant to session compromise because theft of browser cookies and similar secrets can enable downstream account takeover and abuse of authenticated web sessions. Reporting also places Lumar in the broader ecosystem of malware-as-a-service and traffer-enabled cybercrime operations, where operators combine commodity malware, evasive builds, and scalable distribution infrastructure to maximize infections.
High-confidence reporting supports Lumar as an infostealer targeting Windows systems, with credential and session-related data theft as a primary function. It has been linked to criminal campaigns rather than espionage activity, and its observed use fits the broader financially motivated stealer ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
In this scheme, victims click a software download button on a site claiming to provide access to a sought-after program, and thereafter are redirected through a variety of websites (many ending in *.click or *.xyz), before eventually being presented with a file to download, which contains the malware.
This model does not allow infostealer malware, which runs with the permissions of the logged user, to steal secrets stored in Chrome browser.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer mentioned as one of the malware families whose developers claimed to have bypassed Chrome’s App-Bound Encryption.
An infostealer referenced as continuing to steal Chrome cookie data and other secrets despite App-Bound Encryption protections.
Инфостилер, также известный как PovertyStealer; упомянут среди семейств, заявлявших об обходе Chrome Application-Bound Encryption.
Named information-stealing malware listed as detectable via favicon hash hunting of exposed infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.