Info Stealer
Lumma Stealer
First seen: 2022-08 • Status: active
Currently Active Threat
Lumma is a password-stealing program that criminals can rent for about $250/month. It grabs saved passwords from your browsers, steals cryptocurrency wallet data, and even tries to bypass two-factor authentication. It often spreads through fake software downloads or sketchy ads.
Overview
Lumma Stealer is a popular information-stealing malware sold as Malware-as-a-Service (MaaS). It targets browser credentials, cryptocurrency wallets, and two-factor authentication extensions. Lumma is distributed through various channels including fake software downloads, malvertising, and phishing campaigns.
Also Known As
LummaC2, Lumma, LummaStealer
How It Spreads
- • Malicious Google Ads leading to fake software sites
- • Fake software crack downloads
- • Phishing emails with malicious attachments
- • Compromised legitimate websites
- • YouTube video descriptions with malicious links
What It Does
- • Steals browser saved passwords and cookies
- • Extracts cryptocurrency wallet data
- • Captures 2FA browser extension data
- • Harvests Discord and Telegram tokens
- • Collects system and installed software information
- • Takes screenshots
Is your business exposed?
Target Platforms
Windows 10, Windows 11
Detection Tips
- • Monitor for processes accessing browser credential files
- • Alert on outbound connections to newly registered domains
- • Watch for processes reading cryptocurrency wallet files
- • Detect execution from Downloads or Temp folders
- • Monitor PowerShell execution with encoded commands
MITRE ATT&CK Techniques
T1555, T1539, T1552, T1113, T1005
If You're Infected
- 1.
Isolate infected machine from network
- 2.
Reset ALL passwords - browsers save everything
- 3.
Revoke and regenerate 2FA codes where possible
- 4.
Transfer cryptocurrency to new wallets immediately
- 5.
Run full antivirus scan and consider reimaging
- 6.
Enable MFA on all accounts (use hardware keys if possible)
Related Malware
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required