Lumma Stealer

Stealer

⚠️ Overview

Lumma Stealer, also tracked as LummaC2, is an information-stealing malware first observed in August 2022, sold as a malware-as-a-service (MaaS) on Russian-language underground forums with subscriptions ranging from $250 to $1,000 per month. It is developed by an actor known as "Lumma" and is written in C/C++ with a focus on exfiltrating browser credentials, cryptocurrency wallets, two-factor authentication (2FA) codes, and system metadata.

🔧 Technical Capabilities

Lumma Stealer targets over 70 Chromium-based browsers and 10 Firefox-based browsers, extracting saved passwords, cookies, and autofill data via process injection (MITRE ATT&CK T1055). It also steals from 20+ cryptocurrency wallet extensions, including MetaMask, Trust Wallet, and Coinbase Wallet, by reading browser extension storage files. The malware uses a Telegram bot as its command-and-control (C2) channel, sending stolen data via HTTP POST requests to attacker-controlled servers, and supports a reverse proxy for outbound communication. It evades sandbox environments by checking system language, screen resolution (e.g., 800x600), and disk size below 60 GB, then deleting itself after successful exfiltration (T1070.004). Persistence is achieved via registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or scheduled tasks (T1053.005). Lumma Stealer also collects system fingerprint data, including CPU, GPU, username, and installed software, to profile victims (T1082).

📜 History & Notable Incidents

Lumma Stealer first appeared in August 2022 on Russian forums, later expanding its reach through malvertising campaigns, fake software downloads (e.g., cracked Windows utilities), and GitHub repositories hosting trojanized installers. In 2023, it was involved in a widespread campaign using fake CAPTCHA pages to trick users into running PowerShell commands that download and execute the stealer (Ursnif-related delivery). No specific high-profile victim or law enforcement action has been publicly documented, but the malware has been consistently updated to target new wallets and browser versions.

🔍 Detection Indicators

Behavioral indicators include the creation of files in %TEMP% with random .exe or .dll names, network connections to Telegram API endpoints (api.telegram.org), and registry modifications under Run keys. Known static hashes for Lumma samples include SHA-256 values published by vendors like Malwarebytes (e.g., 5a3e...f2b1 — see Malwarebytes Threat Center). The malware leaves traces of DLL sideloading (e.g., LoadLibrary calls to ntdll.dll) and writes configuration data to the registry under HKCUSoftware.

☠️ Risk & Impact

Primary damage includes theft of digital identities (passwords and cookies), cryptocurrency wallet private keys, and session tokens, enabling account takeover and financial theft. The malware has affected individual users and small businesses, particularly those in cryptocurrency and finance sectors, with stolen data resold on dark web markets. Loss of credentials can lead to lateral movement and ransomware deployment by secondary threat actors.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) tools with rules alerting on suspicious PowerShell executions and outbound Telegram API connections, enforce application allowlisting, and block known malicious IPs from threat intelligence feeds. Organizations should also implement credential hygiene (e.g., MFA, password managers) and regularly scan for unauthorized registry run keys and scheduled tasks.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.