logo

Lumma information stealer infrastructure disrupted

ID: 25a3e001-939b-5ce1-9f70-3c6b405d94ba

STIX ID: report--25a3e001-939b-5ce1-9f70-3c6b405d94ba

Feed Name: Malwarebytes Blog

Threat Score
80/100

Date Published: 2025-05-22

Date Updated: 2026-04-28

...
...

The U.S. Department of Justice and Microsoft disrupted the Lumma infostealer (LummaC/LummaC2) by seizing about 2,300 domains used as user panels for this MaaS operation that has infected hundreds of thousands to millions of systems; Lumma steals credentials, cookies, autofill data, FTP/email data, 2FA tokens/backup codes, and cryptocurrency wallets. The takedown redirects domains to Microsoft-controlled sinkholes for monitoring, and the report advises users to employ strong unique passwords, MFA, updated software, anti-malware, and cautious handling of emails and downloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.