logo

Lumma Stealer — A Proliferating Threat in the Cybercrime Landscape

ID: fb9b127a-7dbf-507b-8e71-6f23d3576338

STIX ID: report--fb9b127a-7dbf-507b-8e71-6f23d3576338

Feed Name: BeGoodToAll

Threat Score
85/100

Date Published: 2025-07-26

Date Updated: 2026-04-19

Author: BeGoodToAll

...
...

**Executive Summary:** Lumma Stealer (aka LummaC2/Lummac) is a prolific Malware-as-a-Service information stealer first observed in August 2022 and rapidly evolved into a dominant infostealer used in widespread campaigns; the report covers its development timeline, sophisticated evasion and persistence techniques (obfuscation, anti-sandbox mouse-tracking, fileless/PowerShell delivery, DLL side-loading), distribution vectors (phishing, malvertising, trojanized/cracked apps, ClickFix fake CAPTCHAs), multi-tiered resilient C2 infrastructure with numerous domains/IPs, extensive IOCs (hashes, URLs, user-agent "TeslaBrowser/5.5"), attribution to the developer alias "Shamel," market impact, large infection counts, and recommended mitigations such as EDR/NGAV, behavior-based monitoring, MFA, patching, network segmentation and threat intelligence integration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.