Lumma Stealer
MITRE ATT&CK: S1213 View on attack.mitre.org
Aliases: LummaStealer, LummaC2 Stealer, Lumma Stealer
- First seen
- 2022-01-01 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 10150 (9277 malicious)
- Last IoC activity
- 2026-09-02 04:11:39
- Profile updated
- 2026-07-07 13:13:44
Targeted industries: financial-services technology-and-telecommunications retail-and-hospitality
Context
Lumma Stealer is an information stealer malware family in use since at least 2022. Lumma Stealer is a Malware as a Service (MaaS) where captured data has been sold in criminal markets to Initial Access Brokers.
Recent IoC activity
9,329 malicious indicators in Maltiverse are attributed to Lumma Stealer (S1213). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 737 Sigma rules
Malware & tools used
- Debugger Evasion (attack-pattern)
- AutoHotKey & AutoIT (attack-pattern)
- Supply Chain Compromise (attack-pattern)
- Screen Capture (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Security Software Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Process Hollowing (attack-pattern)
- Electron Applications (attack-pattern)
- System Checks (attack-pattern)
- Mshta (attack-pattern)
- DLL (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Browser Extensions (attack-pattern)
- Local Data Staging (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- User Execution (attack-pattern)
- Masquerade File Type (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- PowerShell (attack-pattern)
- Automated Collection (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Malicious File (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
Used by threat actors
- "Fake CAPTCHA" Lumma Stealer Distribution Campaign (campaign)
- Lumma Stealer Distribution via Spoofed Webpages (campaign)
- November 2023-May 2025 Lumma Stealer Deployment Activity (campaign)
Exploited vulnerabilities
- CVE-2024-21412 (vulnerability)
Detection rules
- RUSSIANPANDA_Lummac2 (yara-rule)
- DITEKSHEN_MALWARE_Win_Unknown_Packedloader_01 (yara-rule)
Reports & references
- cloud.google.com — Unc5537 Snowflake Data Theft Extortion (report)
- proofpoint.com — Clipboard Compromise Powershell Self Pwn (report)
- research.checkpoint.com — Stargazers Ghost Network (report)
- Kaspersky — 115663 (report)
- Trend Micro — Ai Assisted Fake Github Repositories (report)
- Trend Micro — Lumma Stealer Returns (report)
- Trend Micro — The Impact Of Water Kurita Lumma Stealer Doxxing (report)
- Trend Micro — Lumma Stealer Browser Fingerprinting (report)
- Microsoft — Octo Tempest Crosses Boundaries To Facilitate Extortion Encryption And Destruction (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- proofpoint.com — Update Fake Updates Two New Actors And New Mac Malware (report)
- blog.sekoia.io — Exposing Fakebat Loader Distribution Methods And Adversary Infrastructure (report)
- blog.sekoia.io — Interlock Ransomware Evolving Under The Radar (report)
- trustwave.com — Pronsis Loader A Jphp Driven Malware Diverging From D3Fck Loader (report)
- rapid7.com — Fake Update Utilizes New Idat Loader To Execute Stealc And Lumma Infostealers (report)
- fortinet.com — Exploiting Cve 2024 21412 Stealer Campaign Unleashed (report)
- cloudsek.com — Threat Actors Abuse Ai Generated Youtube Videos To Spread Stealer Malware (report)
- any.run — Crackedcantil Breakdown (report)
- proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
- insights.bridewell.com — Cyber%20Threat%20Intelligence%20Report%202025 (report)
- esentire.com — Fake Browser Updates Delivering Bitrat And Lumma Stealer (report)
- rapid7.com — Ongoing Social Engineering Campaign Refreshes Payloads (report)
- orangecyberdefense.com — Cybersoc Insights Analyse Einer Black Basta Angriffskampagne (report)
- bitdefender.com — Lummastealer Second Life Castleloader (report)
- censys.com — A Beginners Guide To Hunting Open Directories (report)
External references
- mitre-attack — S1213
- LummaStealer
- TrendMicro LummaStealer 2025
- Fortinet LummaStealer 2024
- Cybereason LumaStealer Undated
- Netskope LummaStealer 2025
- Qualys LummaStealer 2024
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy