logo

Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations

ID: 831bf8b4-18ea-5546-8842-29827527f2c7

STIX ID: report--831bf8b4-18ea-5546-8842-29827527f2c7

Feed Name: CISA Cybersecurity Advisories

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-04-19

Author: CISA

...
...

**Executive Summary:** The FBI and CISA advisory documents LummaC2, an actively observed infostealer (Nov 2023–May 2025) distributed via spearphishing and spoofed software that runs primarily in memory, decrypts C2 domains, receives JSON commands to steal browser data, credentials, cryptocurrency wallets, and MFA details, and provides extensive IOCs (file hashes, DLL names, and domains) plus mitigation and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.