Info Stealer

Lumma Stealer

First seen: 2022-08 • Status: active

Currently Active Threat

Lumma is a password-stealing program that criminals can rent for about $250/month. It grabs saved passwords from your browsers, steals cryptocurrency wallet data, and even tries to bypass two-factor authentication. It often spreads through fake software downloads or sketchy ads.

Overview

Lumma Stealer is a popular information-stealing malware sold as Malware-as-a-Service (MaaS). It targets browser credentials, cryptocurrency wallets, and two-factor authentication extensions. Lumma is distributed through various channels including fake software downloads, malvertising, and phishing campaigns.

Also Known As

LummaC2, Lumma, LummaStealer

How It Spreads

  • Malicious Google Ads leading to fake software sites
  • Fake software crack downloads
  • Phishing emails with malicious attachments
  • Compromised legitimate websites
  • YouTube video descriptions with malicious links

What It Does

  • Steals browser saved passwords and cookies
  • Extracts cryptocurrency wallet data
  • Captures 2FA browser extension data
  • Harvests Discord and Telegram tokens
  • Collects system and installed software information
  • Takes screenshots

Is your business exposed?

Target Platforms

Windows 10, Windows 11

Detection Tips

  • Monitor for processes accessing browser credential files
  • Alert on outbound connections to newly registered domains
  • Watch for processes reading cryptocurrency wallet files
  • Detect execution from Downloads or Temp folders
  • Monitor PowerShell execution with encoded commands

MITRE ATT&CK Techniques

T1555, T1539, T1552, T1113, T1005

If You're Infected

  1. 1.

    Isolate infected machine from network

  2. 2.

    Reset ALL passwords - browsers save everything

  3. 3.

    Revoke and regenerate 2FA codes where possible

  4. 4.

    Transfer cryptocurrency to new wallets immediately

  5. 5.

    Run full antivirus scan and consider reimaging

    Malwarebytes

  6. 6.

    Enable MFA on all accounts (use hardware keys if possible)

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required