LummaStealer activity spikes post-law enforcement disruption
ID: 5a21d787-961b-5dd9-a49d-db6c92094416
STIX ID: report--5a21d787-961b-5dd9-a49d-db6c92094416
Feed Name: Security Affairs
Bitdefender observed a sharp rebound in LummaStealer (a Malware-as-a-Service infostealer) activity after 2025 takedowns, driven by evolving social-engineering lures (fake CAPTCHAs, bogus Steam updates) and the rising use of CastleLoader as an in-memory loader; the report documents distribution chains, loader behaviors, infrastructure overlap, global infection prevalence (noted infections in the hundreds of thousands), ties to ransomware groups, and recommended mitigations such as avoiding untrusted downloads and enabling MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
