Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
ID: 831bf8b4-18ea-5546-8842-29827527f2c7
STIX ID: report--831bf8b4-18ea-5546-8842-29827527f2c7
Feed Name: CISA Cybersecurity Advisories
Threat Score
**Executive Summary:** The FBI and CISA advisory documents LummaC2, an actively observed infostealer (Nov 2023–May 2025) distributed via spearphishing and spoofed software that runs primarily in memory, decrypts C2 domains, receives JSON commands to steal browser data, credentials, cryptocurrency wallets, and MFA details, and provides extensive IOCs (file hashes, DLL names, and domains) plus mitigation and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
