Storm-2460
Aliases: Lumma Stealer
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:20:55
Targeted industries: technology-and-telecommunications financial-services retail-and-hospitality
Context
Storm-2460 is a threat actor that has exploited elevation of privilege vulnerabilities to deploy PipeMagic malware and ransomware, enabling them to escalate access within compromised environments. They have been observed using the certutil utility to download malware from compromised legitimate third-party websites. Ransomware activity associated with Storm-2460 includes file encryption and the deployment of a ransom note named !_READ_ME_REXX2_!.txt. Microsoft recommends prioritizing security updates for elevation of privilege vulnerabilities to mitigate the impact of this actor's activities.
Reports & references
- Microsoft — Exploitation Of Clfs Zero Day Leads To Ransomware Activity (report)
- raw.githubusercontent.com — Microsoftmapping (report)
Attributed from
- "Fake CAPTCHA" Lumma Stealer Distribution Campaign (campaign)
- Lumma Stealer Distribution via Spoofed Webpages (campaign)
- November 2023-May 2025 Lumma Stealer Deployment Activity (campaign)