logo

Behind the Curtain: How Lumma Affiliates Operate

ID: a9970bb4-e0be-5f69-a19f-e3e882bc384d

STIX ID: report--a9970bb4-e0be-5f69-a19f-e3e882bc384d

Feed Name: Recorded Future Blog

Threat Score
78/100

Date Published: 2025-08-20

Date Updated: 2026-04-28

...
...

This report analyzes the Lumma infostealer MaaS and its affiliates, revealing a large, resilient, and interconnected information-stealing ecosystem that leverages proxies, VPNs, anti-detect browsers, crypting/exploit services, SMS/phone services, and underground forums to distribute malware, monetize stolen data, and run parallel scams (including rental fraud). Insikt Group documents previously unreported tooling (e.g., cracked email validators, phishing page generators), the use of additional stealers (Vidar, Stealc, Meduza), hosting and AV-testing services, and provides IoCs and ATT&CK mappings to help defenders detect and mitigate infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.