{"urls":["https://0xmrmagnezi.github.io/malware%20analysis/LummaStealer/","https://0xtoxin-labs.gitbook.io/malware-analysis/malware-analysis/lummac2-breakdown#chrome-extensions-crx","https://any.run/cybersecurity-blog/crackedcantil-breakdown/","https://blog.cyble.com/2023/01/06/lummac2-stealer-a-potent-threat-to-crypto-users/","https://blog.reveng.ai/one-clickfix-and-lummastealer-recaptchas-our-attention-part-1/","https://blog.sekoia.io/exposing-fakebat-loader-distribution-methods-and-adversary-infrastructure/","https://blog.sekoia.io/interlock-ransomware-evolving-under-the-radar/","https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/","https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/","https://censys.com/a-beginners-guide-to-hunting-open-directories/","https://cert-agid.gov.it/news/analisi-di-una-campagna-lumma-stealer-con-falso-captcha-condotta-attraverso-domino-italiano-compromesso/","https://certego.github.io/website/blog/lummastealer/","https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware/","https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion","https://darktrace.com/blog/the-rise-of-the-lumma-info-stealer","https://denwp.com/anatomy-of-a-lumma-stealer/","https://denwp.com/dissecting-lumma-malware/","https://g0njxa.medium.com/approaching-stealers-devs-a-brief-interview-with-lummac2-94111d4b1e11","https://gridinsoft.com/spyware/lumma-stealer","https://info.spamhaus.com/hubfs/Botnet%20Reports/Q4%202023%20Botnet%20Threat%20Update.pdf","https://infrawatch.app/blog/ghostsocks-lummas-partner-in-proxy","https://insights.bridewell.com/hubfs/Cyber%20Threat%20Intelligence%20Report%202025.pdf","https://insights.loaderinsight.agency/posts/vidar-build-id-correlation/","https://intelinsights.substack.com/p/bulletproof-hosting-hunt","https://labs.guard.io/deceptionads-fake-captcha-driving-infostealer-infections-and-a-glimpse-to-the-dark-side-of-0c516f4dc0b6","https://mandarnaik016.in/blog/2024-10-05-malware-analysis-lumma-stealer/","https://medium.com/@raghavtiresearch/lumma-stealer-a-proliferating-threat-in-the-cybercrime-landscape-b5cdc3de44a4","https://medium.com/@s.lontzetidis/lumma-2024-dominating-the-info-stealer-market-070e7d8fa3d6","https://medium.com/s2wblog/lumma-stealer-targets-youtubers-via-spear-phishing-email-ade740d486f7","https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/","https://outpost24.com/blog/everything-you-need-to-know-lummac2-stealer","https://outpost24.com/blog/lummac2-anti-sandbox-technique-trigonometry-human-detection/","https://research.checkpoint.com/2024/stargazers-ghost-network/","https://resource.redcanary.com/rs/003-YRU-314/images/2025ThreatDetectionReport_RedCanary.pdf","https://ryan-weil.github.io/posts/LUMMA-STEALER/","https://securelist.com/angry-likho-apt-attacks-with-lumma-stealer/115663/","https://spycloud.com/blog/asgard-protector-crypter-analysis/","https://spycloud.com/blog/lummac2-malware-stealthier-capabilities/","https://synthient.com/blog/ghostsocks-from-initial-access-to-residential-proxy","https://therecord.media/microsoft-disrupts-fox-tempest-malware-signing-service","https://twitter.com/Ishusoka/status/1614028229307928582","https://twitter.com/fumik0_/status/1559474920152875008","https://twitter.com/sekoia_io/status/1572889505497223169","https://v4ensics.gr/lumma-stealer-a-tale-that-starts-with-a-fake-captcha/","https://viuleeenz.github.io/posts/2024/02/understanding-peb-and-ldr-structures-using-ida-and-lummastealer/","https://viuleeenz.github.io/posts/2024/03/understanding-api-hashing-and-build-a-rainbow-table-for-lummastealer/","https://www.0x1c.zip/0001-lummastealer/","https://www.bitdefender.com/en-us/blog/labs/lummastealer-second-life-castleloader","https://www.cloudsek.com/blog/threat-actors-abuse-ai-generated-youtube-videos-to-spread-stealer-malware","https://www.cybereason.com/blog/threat-analysis-rise-of-lummastealer","https://www.darktrace.com/blog/phantom-footprints-tracking-ghostsocks-malware","https://www.elastic.co/security-labs/a-wretch-client","https://www.elastic.co/security-labs/ghostpulse-haunts-victims-using-defense-evasion-bag-o-tricks","https://www.esentire.com/blog/fake-browser-updates-delivering-bitrat-and-lumma-stealer","https://www.esentire.com/blog/the-case-of-lummac2-v4-0","https://www.europol.europa.eu/media-press/newsroom/news/europol-and-microsoft-disrupt-world%E2%80%99s-largest-infostealer-lumma","https://www.fortinet.com/blog/threat-research/exploiting-cve-2024-21412-stealer-campaign-unleashed","https://www.fortinet.com/blog/threat-research/lumma-variant-on-youtube","https://www.gendigital.com/blog/insights/research/remus-64bit-variant-of-lumma-stealer","https://www.googlecloudcommunity.com/gc/Community-Blog/Finding-Malware-Unveiling-LUMMAC-V2-with-Google-Security/ba-p/899110","https://www.group-ib.com/blog/clickfix-the-social-engineering-technique-hackers-use-to-manipulate-victims/","https://www.intrinsec.com/lumma_stealer_actively_deployed_in_multiple_campaigns/","https://www.intrinsec.com/wp-content/uploads/2024/12/TLP-CLEAR-CryptBot-Hunting-for-intial-access-vectors.pdf","https://www.kroll.com/en/insights/publications/cyber/lummastealer-delivered-via-powershell-social-engineering","https://www.malware-traffic-analysis.net/2024/03/07/index.html","https://www.mcafee.com/blogs/other-blogs/mcafee-labs/behind-the-captcha-a-clever-gateway-of-malware/","https://www.mcafee.com/blogs/other-blogs/mcafee-labs/clickfix-deception-a-social-engineering-tactic-to-deploy-malware/","https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/","https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/","https://www.netskope.com/blog/lumma-stealer-fake-captchas-new-techniques-to-evade-detection","https://www.orangecyberdefense.com/de/blog/threat/cybersoc-insights-analyse-einer-black-basta-angriffskampagne","https://www.paloaltonetworks.com/blog/security-operations/a-deep-dive-into-malicious-direct-syscall-detection/","https://www.proofpoint.com/us/blog/threat-insight/clipboard-compromise-powershell-self-pwn","https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape","https://www.proofpoint.com/us/blog/threat-insight/update-fake-updates-two-new-actors-and-new-mac-malware","https://www.rapid7.com/blog/post/2023/08/31/fake-update-utilizes-new-idat-loader-to-execute-stealc-and-lumma-infostealers/","https://www.rapid7.com/blog/post/2024/08/12/ongoing-social-engineering-campaign-refreshes-payloads/","https://www.trellix.com/blogs/research/how-attackers-repackaged-a-threat-into-something-that-looked-benign/","https://www.trellix.com/en-ca/blogs/research/lumma-stealer-analysis/","https://www.trendmicro.com/en_us/research/25/c/ai-assisted-fake-github-repositories.html","https://www.trendmicro.com/en_us/research/25/g/lumma-stealer-returns.html","https://www.trendmicro.com/en_us/research/25/j/the-impact-of-water-kurita-lumma-stealer-doxxing.html","https://www.trendmicro.com/en_us/research/25/k/lumma-stealer-browser-fingerprinting.html","https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pronsis-loader-a-jphp-driven-malware-diverging-from-d3fck-loader/","https://www.varist.com/blogs-news/malvertisements-fake-captchas","https://www.youtube.com/watch?v=kHU_sPtubCk","https://www.youtube.com/watch?v=lmMA4WYJEOY","https://www.zynap.com/blog/defensive-rootkits-engineering-kernel-level-malware-analysis-ring-0/","https://x.com/CERTCyberdef/status/1900460479778030013"],"uuid":"a14270e4-2b5e-4a90-9ccd-0b68690dbc3e","notes":[],"sources":[],"updated":"2026-09-07","alt_names":["LummaC2 Stealer"],"attribution":["Angry Likho"],"common_name":"Lumma Stealer","description":"Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor \"Shamel\", who goes by the alias \"Lumma\". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent \"TeslaBrowser/5.5\".\" The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell.","library_entries":["0x1c:20240621:0001:ab3887b","0xmrmagnezi:20240925:lumma:9302edc","0xtoxin:20230409:lummac2:b5f84e3","alintanahin:20250218:malvertisements:c0046a5","begoodtoall:20250727:lumma:d872f6e","bitam:20250618:wretch:f299e89","bourgue:20240702:exposing:0337f1a","bridewell:20250624:2025:d75317d","canary:20250312:2025:6a8afce","certagid:20250113:analisi:a1090f9","chechik:20240213:deep:7209033","cruz:20250322:back:efffc1d","cruz:20251016:shifts:96e2d39","cruz:20251113:increase:b864589","cyble:20230106:lummac2:4913d43","darktrace:20230906:rise:496a284","desimone:20231027:ghostpulse:d3a821a","dsouza:20250430:finding:e1bd3f1","duncan:20240307:20240307:0e2639b","embeeresearch:20230108:malware:96359e1","embeeresearch:20240108:malware:96359e1","embeeresearch:20240722:beginners:ec16cf8","esentire:20230907:case:fd86e6b","esentire:20240529:fake:fb78f83","europol:20250520:europol:0f78162","evans:20260326:phantom:2461c96","fantini:20250624:malware:1dae6e2","fortinet:20240723:exploiting:ebdcd7c","froes:20250123:lumma:fa4230f","fumik0:20220816:lumma:76d543a","g0njxa:20231116:approaching:82a667f","glass:20241112:lummastealer:519626e","goldberg:20250509:lumma:4769f88","greig:20260519:microsoft:bf8f9d9","groupib:20250313:clickfix:0acf5b0","hahn:20250127:malware:7826fbf","holzner:20250415:cybersoc:7a79ee7","houspanossian:20240617:info:5464bca","intelligence:20231025:octo:4a72acc","intelligence:20260519:exposing:d8c7392","intrinsec:20231017:lumma:ad1631a","intrinsec:20241230:cryptbot:1c5b9c6","ishu:20220113:tweets:31114ef","ishu:20230113:tweets:31114ef","james:20241219:lummac2:439a076","james:20251001:bifrost:aa48c9c","jitu:20240830:anatomy:322db48","jitu:20240909:dissecting:a49e8e8","kaspersky:20250221:angry:785af00","khader:20250421:unmasking:10dbcde","kim:20230227:lumma:9f3f99f","krejsa:20260407:remus:669e940","labs:20240112:spamhaus:1249ec1","lambdamamba:20230130:crackedcantil:6daafee","lambdamamba:20240130:crackedcantil:6daafee","lazar:20260211:lummastealer:aca1d8d","lee:20240822:peaklight:258e9ed","lia:20241017:correlating:dabd625","lin:20240108:deceptive:a2ec81b","lontzetidis:20241228:lumma:cccd70c","m:20230203:threat:055d818","madjar:20241118:security:3223454","mandiant:20240610:unc5537:9f20515","marn:20230405:everything:44474d9","marn:20231120:unveiling:5bde1c0","marn:20260324:defensive:d564111","masada:20250521:disrupting:fb849be","masada:20260519:disruptingfox:5fb2f9d","mateo:20250311:aiassisted:88ea2b5","mcgraw:20240812:ongoing:a4164d7","naik:20241005:malware:dce0459","orlof:20250727:bulletproof:f7c6682","petrus:20250509:lumma:4769f88","pichon:20250314:emmenhtal:d98d1ce","proofpoint:20240617:from:3cbd348","revengai:20250130:one:d89fda5","security:20240213:what:8a63465","sekoia:20220922:tweets:b2e9079","shah:20240711:clickfix:7fdcc61","shah:20240920:behind:b60af0e","strino:20240204:understanding:eee5608","strino:20240324:understanding:b7c33aa","synthient:20250930:ghostsocks:3719660","tal:20241216:deceptionads:61b6380","tdr:20250416:interlock:d355da5","team:20250218:update:31174de","team:20250220:ghostsocks:b175c38","terefos:20240724:stargazers:c697755","tomboc:20241008:pronsis:e3c55ad","v4ensics:20250314:lumma:a79a666","villanueva:20241217:your:90990c2","weil:20241220:deobfuscation:32fbe2f","zargarov:20230831:fake:4b8ef57"]}