logo

LUMMA STEALER STILL ACTIVE? AFTER FBI CRACKDOWN!

ID: e2b27365-07b4-52f9-9902-339038f186a8

STIX ID: report--e2b27365-07b4-52f9-9902-339038f186a8

Feed Name: THE RAVEN FILE

Threat Score
75/100

Date Published: 2025-05-23

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

**Executive summary:** This investigation documents Lumma Stealer activity observed 21–22 May 2025: despite an FBI seizure of ~2,300 public domains, operators quickly reconstituted infrastructure and continued selling harvested credentials and cookies via a Telegram shop; the report includes victim counts (global distribution and country breakdowns), victim IP lists and IOCs (domains and IP addresses) demonstrating active exploitation and ongoing criminal commerce of stolen data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.