Lumma Stealer, one of the most dangerous information-stealing malware, has been successfully dismantled by Microsoft and global law enforcement agencies. Microsoft’s Digital Crimes Unit (DCU) has just announced an international campaign to neutralize Lumma Stealer, a variant of information-stealing malware widely used by criminal groups and threat actors worldwide.
Between March 16 and May 16, 2025, Microsoft identified over 394,000 Windows computers infected with Lumma. Following a court order from the U.S. District Court for the Northern District of Georgia, Microsoft seized 2,300 domains that formed the backbone of Lumma’s infrastructure. The U.S. Department of Justice also seized Lumma’s command-and-control structure and disrupted the online marketplaces selling Lumma.
According to a Microsoft spokesperson, Lumma is easy to distribute, difficult to detect, and can be programmed to bypass certain security defenses, making it a top tool for cybercriminals and online threat actors. It is used by cybercriminals as an effective tool to gain initial access to accounts or sensitive information to facilitate other types of cybercrime, such as ransomware and fraud.
How Lumma Stealer Works and Its Capabilities
Lumma Stealer, also known as LummaC2, is a Malware-as-a-Service (MaaS) capable of stealing data from various browsers. Cybercriminals have used Lumma to steal passwords, credit cards, bank account information, and cryptocurrency wallets in major attack campaigns in recent years.
LummaC2 is an Infostealer operating as Malware-as-a-Service that has been active since late 2022 and has become increasingly popular among cybercriminals. This malware is capable of collecting login credentials and cookies from browsers, locating locally stored cryptocurrency wallets and extensions, and targeting VPNs along with various internet applications.
Additionally, Lumma collects various types of documents (PDF, DOCX, RTF) from local user profiles and steals metadata from infected machines for further exploitation. This malware spreads through multiple channels, including phishing emails, malicious advertisements, downloads from compromised websites, and fake Captcha challenges.
International Campaign to Eliminate Lumma Stealer
Europol and Microsoft have collaborated to dismantle the world’s largest Infostealer—Lumma. This joint operation targets the sophisticated ecosystem that allows criminals to exploit stolen information on a massive scale. Microsoft has worked with federal courts in Georgia, the U.S. Department of Justice, Europol, and the Japan Cybercrime Control Center to dismantle Lumma’s infrastructure.
The seized domains are now redirected to sinkholes controlled by Microsoft, both protecting users and providing analysts with new detailed information on malicious activity. With its infrastructure dismantled, the Lumma business has effectively been shut down.
Microsoft has identified the primary developer behind Lumma as a Russian hacker known by the alias “Shamel.” In a recent interview with a cybersecurity researcher, this hacker claimed to have approximately 400 active customers. This may no longer be true, as Windows Defender and other Microsoft endpoint security tools can now reliably detect this nearly neutralized malware.
Summary: The international campaign led by Microsoft has successfully dismantled Lumma Stealer, one of the most dangerous information-stealing malwares today. By neutralizing over 2,300 malicious domains and seizing the command-and-control structure, Microsoft and its partners have protected over 394,000 Windows computers from password, credit card, and cryptocurrency wallet theft. Disrupting the tools frequently used by cybercriminals can have a significant and long-lasting impact on cybercrime, as rebuilding malicious infrastructure and searching for new exploitation tools is time-consuming and costly. Users should regularly update security software and use reliable antivirus solutions to protect personal and business information from similar threats in the future.


