Police car on the street showing international law enforcement action on infostealer malware

Raid on Lumma Infostealer Malware Results in Seizure of Control Panel, 2,300 Domains

A major threat actor has been crippled by an international law enforcement action, as the Lumma infostealer malware operation saw its control panel seized along with infrastructure dwelling in Europe and Japan. This was supplemented by Microsoft seizing some 2,300 domains belonging to the group, which has infected over 394,000 Windows computers globally.

Public-private partnership delivers heavy blow to Lumma infostealer malware

The coordinated raid took place in early May and involved law enforcement entities from the US, Europe and Japan along with Microsoft’s Digital Crimes Unit and a collection of other private security and IT service providers such as ESET, Cloudflare, CleanDNS and Lumen.

Lumma is an infostealer malware service that has been available since December 2022 that targets Windows and MacOS systems and exfiltrates a broad variety of user data including credentials, cryptocurrency wallet contents and stored credit cards and browsing history. Criminals pay $250 to $1,000 to access the service. It attacks a wide range of commonly used applications and web browsers to harvest this information, and has been one of the most popular malware-as-a-service outfits of its type since 2023.

Lumma’s operation not only included providing the infostealer malware, but also hosting one of the world’s largest underground forums for buying and selling stolen personal information. That market is now out of business after the Department of Justice (DOJ) seized the Lumma control panel. It was already the largest infostealer malware service provider in the world by several metrics, but information from ESET indicates that it was still in the midst of aggressive expansion plans with 74 new domains emerging each week and a total of 3,353 deployed over the past year. In total Lumma’s malware is thought to have been deployed against about 1.7 million targets during the group’s lifetime.

Lumma made use of broad variety of attack tactics

Lumma rose to the top of the infostealer malware market in no small part due to being more feature-rich than prior infostealers, which had previously relied on relatively crude bulk messaging tactics or taking advantage of an exploit that could be patched at any time. Lumma’s product is regularly updated and maintained and rotates through a variety of tactics to include malvertising, cracked versions of popular apps that have had trojans inserted, and a roster of compromised websites that secretly host malicious JavaScript. Bulk emailing also remains an option, but in a more sophisticated way; a Microsoft report notes a phishing campaign directed at organizations in Canada that targeted thousands of employees but implemented recipient-specific variations and deployed a fake captcha mocked up to look like those used by Google.

Lumma is thought to be Russia-based, which makes it extremely difficult to completely eradicate. However, the blow to its operations will likely have at least some positive near-term effects due to its status as a “go-to” infostealer malware for many other groups. For example, the “Scattered Spider” team that made news recently for its raid on major UK retailers regularly makes use of it.

Nevertheless, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint advisory on the Lumma infostealer malware on May 21 that provides detailed information on the group’s known tactics and procedures. Recommended mitigation measures include monitoring API calls that attempt to retrieve system information, implementing application controls that prevent installation and execution of portable versions of unauthorized remote access software, and regularly monitoring and reviewing registry changes and access logs.

Major threat actors have bounced back from raids of this type before, however. Scattered Spider is one example, re-emerging in recent weeks to grab headlines with its ransomware attacks after undergoing arrests of key figures in late 2024. An even more direct comparison is the Bumblebee infostealer malware, thought to have been fatally crippled by Europol as part of its massive “Operation Endgame” campaign against botnets in mid-2024. But by October the malware had re-emerged with an even more sophisticated attack chain than it had ever previously made use of; Emotet went through a similar raid-and-revival pattern in 2021.

Lumma must thus remain on the threat radar for the time being, and it often spreads through unconventional means. Security researchers have found it in malicious GitHub comments made to look like valid updates, sites that purport to generate deepfakes, and malvertising passed through legitimate ad networks among other sources. But the bulk of prevention boils down to phishing awareness, as all of these sources are essentially attempting to mislead the user and get them to click on a link or download that should be at least somewhat suspicious.

Ensar Seker, CISO at SOCRadar, notes that these tactics will also be employed by numerous other threat actors: “The coordinated takedown of Lumma Stealer’s infrastructure marks a pivotal moment in combating the proliferation of Malware-as-a-Service (MaaS) platforms. Lumma Stealer, also known as LummaC2, has been a formidable tool in the cybercriminal arsenal, facilitating the theft of sensitive data including credentials, financial information, and cryptocurrency wallets from nearly 400,000 Windows systems globally between March and May 2025. This operation, led by Microsoft’s Digital Crimes Unit in collaboration with international law enforcement agencies, successfully seized over 2,300 domains integral to Lumma’s operations and dismantled its command-and-control infrastructure. Such actions not only disrupt the immediate threat but also send a clear message to cybercriminals about the increasing capabilities and resolve of global cybersecurity alliances. However, the resilience of such malware underscores the necessity for continuous vigilance. Lumma’s ability to adapt employing phishing, malvertising, and exploiting trusted platforms highlights the evolving tactics of threat actors. While this takedown is a commendable achievement, it also serves as a reminder of the persistent and evolving nature of cyber threats. Ongoing collaboration between private sector entities and international law enforcement is essential to stay ahead.”