Lumma Stealer

MITRE ATT&CK: S1213 View on attack.mitre.org

Aliases: LummaStealer, LummaC2 Stealer, Lumma Stealer

First seen
2022-01-01 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Operating systems
windows
Related IoCs
10150 (9277 malicious)
Last IoC activity
2026-09-02 04:11:39
Profile updated
2026-07-07 13:13:44

Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality

Context

Lumma Stealer is an information stealer malware family in use since at least 2022. Lumma Stealer is a Malware as a Service (MaaS) where captured data has been sold in criminal markets to Initial Access Brokers.

Recent IoC activity

9,329 malicious indicators in Maltiverse are attributed to Lumma Stealer (S1213). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample 86fbbe944f963d7ecfe313d9fa437594db2e8122973ba36ac71b2051063d5490 2026-09-03 2
file sample 871de398ab9f199d5598614eb6701caa8b39d36fd004c2b71136ec23d3fe511d 2026-09-03 2
file sample 87252d3c1de3dcefbd12de44b7345b00b9bdace2e4b5f00d02d197078cf8e9c3 2026-09-03 3
URL https://klipdalygeo.shop/ginni.mp4 2026-09-03 1
URL https://ftargett.top/dsANGt 2026-09-03 1
URL https://globekpey.bet/api 2026-09-03 1
hostname ultahost.gl 2026-09-03 2
file sample 3c74e8c9c3694e4036fea99eb08ba0d3502ad3fe2158432d0efdfaacd9763c35 2026-09-03 3
file sample 86ac79d7d3fd1d50c8e00da55a888081e21047afa61df076ea8c295f1bedf710 2026-09-03 3
hostname dismissalcylinderhostw.shop 2026-09-03 1
hostname perfomnjshin.cyou 2026-09-03 1
hostname chincenterblandwka.pw 2026-09-03 1
hostname superyf.click 2026-09-03 1
hostname guardeduppe.com 2026-09-03 1
hostname criolqs.cyou 2026-09-03 1
hostname medikalbitkisel.net 2026-09-03 1
hostname subnorrepg.run 2026-09-03 1
hostname sneg.cc 2026-09-03 1
hostname salmonqw.live 2026-09-03 1
hostname languagedscie.shop 2026-09-03 1

Detection coverage

  • 2 YARA rules
  • 737 Sigma rules

Malware & tools used

  • Debugger Evasion (attack-pattern)
  • AutoHotKey & AutoIT (attack-pattern)
  • Supply Chain Compromise (attack-pattern)
  • Screen Capture (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Electron Applications (attack-pattern)
  • System Checks (attack-pattern)
  • Mshta (attack-pattern)
  • DLL (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Browser Extensions (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • User Execution (attack-pattern)
  • Masquerade File Type (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • PowerShell (attack-pattern)
  • Automated Collection (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Malicious File (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)

Used by threat actors

  • "Fake CAPTCHA" Lumma Stealer Distribution Campaign (campaign)
  • Lumma Stealer Distribution via Spoofed Webpages (campaign)
  • November 2023-May 2025 Lumma Stealer Deployment Activity (campaign)

Exploited vulnerabilities

  • CVE-2024-21412 (vulnerability)

Detection rules

  • RUSSIANPANDA_Lummac2 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Unknown_Packedloader_01 (yara-rule)

Reports & references

  • cloud.google.com — Unc5537 Snowflake Data Theft Extortion (report)
  • proofpoint.com — Clipboard Compromise Powershell Self Pwn (report)
  • research.checkpoint.com — Stargazers Ghost Network (report)
  • Kaspersky — 115663 (report)
  • Trend Micro — Ai Assisted Fake Github Repositories (report)
  • Trend Micro — Lumma Stealer Returns (report)
  • Trend Micro — The Impact Of Water Kurita Lumma Stealer Doxxing (report)
  • Trend Micro — Lumma Stealer Browser Fingerprinting (report)
  • Microsoft — Octo Tempest Crosses Boundaries To Facilitate Extortion Encryption And Destruction (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • proofpoint.com — Update Fake Updates Two New Actors And New Mac Malware (report)
  • blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
  • blog.sekoia.io — Interlock Ransomware Evolving Under The Radar (report)
  • trustwave.com — Pronsis Loader A Jphp Driven Malware Diverging From D3Fck Loader (report)
  • rapid7.com — Fake Update Utilizes New Idat Loader To Execute Stealc And Lumma Infostealers (report)
  • fortinet.com — Exploiting Cve 2024 21412 Stealer Campaign Unleashed (report)
  • cloudsek.com — Threat Actors Abuse Ai Generated Youtube Videos To Spread Stealer Malware (report)
  • any.run — Crackedcantil Breakdown (report)
  • proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
  • insights.bridewell.com — Cyber%20Threat%20Intelligence%20Report%202025 (report)
  • esentire.com — Fake Browser Updates Delivering Bitrat And Lumma Stealer (report)
  • rapid7.com — Ongoing Social Engineering Campaign Refreshes Payloads (report)
  • orangecyberdefense.com — Cybersoc Insights Analyse Einer Black Basta Angriffskampagne (report)
  • bitdefender.com — Lummastealer Second Life Castleloader (report)
  • censys.com — A Beginners Guide To Hunting Open Directories (report)

External references