logo

ESET takes part in global operation to disrupt Lumma Stealer

ID: 9b107b03-b3ef-5089-8ea3-34800974bc58

STIX ID: report--9b107b03-b3ef-5089-8ea3-34800974bc58

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
75/100

Date Published: 2025-05-21

Date Updated: 2026-05-01

...
...

**Executive summary:** ESET participated in a coordinated global disruption of Lumma Stealer, a widely deployed malware-as-a-service infostealer; the report provides technical analysis of static and dynamic properties (C2 lists, LID/UID, J/CID, dynamic configs), distribution vectors, dead-drop resolvers (Steam/Telegram), obfuscation and anti-analysis techniques, telemetry (tens of thousands of samples and ~3,353 unique C&C domains), comprehensive IoCs (file hashes, domains, IPs) and MITRE ATT&CK mappings to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.