3 Sources
[1]
Authorities carry out global takedown of infostealer used by cybercriminals
A consortium of global law enforcement agencies and tech companies announced on Wednesday that they have disrupted the infostealer malware known as Lumma. One of the most popular infostealers worldwide, Lumma has been used by hundreds of what Microsoft calls "cyber threat actors" to steal
[2]
Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals
US, European, and Japanese authorities, along with tech companies including Microsoft and Cloudflare, say they've disrupted Lumma, an infostealer popular with criminal gangs. A consortium of global law enforcement agencies and tech companies announced on Wednesday that they have disrupted the
[3]
Law Enforcement Seize Domains Linked to Seed Phrase Stealing Malware LummaC2 - Decrypt
Lumma is linked to over 1.7 million theft attempts and active in 394,000 global infections, according to Microsoft Law enforcement agencies have seized key infrastructure linked to LummaC2, a malware operation that targeted millions of victims worldwide, including by stealing crypto wallet seed
Share
Copy Link
A consortium of international law enforcement agencies and tech companies have successfully disrupted Lumma, a popular infostealer malware used by cybercriminals to steal sensitive information, including cryptocurrency wallet details.
In a significant cybersecurity operation, a consortium of global law enforcement agencies and tech companies have successfully disrupted the Lumma infostealer malware. This coordinated takedown targeted one of the most popular infostealer tools used by cybercriminals worldwide
1
.
Source: Decrypt
Lumma, also known as LummaC2, has been a go-to tool for hundreds of cyber threat actors. It was used to steal sensitive information including passwords, credit card details, banking information, and cryptocurrency wallet data. Microsoft reported that between March 16 and May 16, 2025, more than 394,000 Windows computers were infected with Lumma malware
2
.The malware's popularity among cybercriminals was evident from its mention in over 21,000 listings on cybercrime forums in the spring of 2024. Lumma's widespread adoption can be attributed to its ease of distribution, difficulty in detection, and ability to bypass certain security defenses
1
.
Source: Wired
The operation involved multiple agencies and companies:
2
.1
.2
.1
.Lumma first emerged on Russian-language cybercrime forums in 2022. The main developer, known by the online handle "Shamel," is believed to be based in Russia. Shamel marketed different tiers of service for Lumma via Telegram and other Russian-language chat forums, allowing cybercriminals to create custom versions of the malware, add distribution tools, and track stolen information through an online portal
3
.Related Stories

Source: Ars Technica
While the use of infostealing malware has surged since 2020, there's been a recent shift towards malware-free attacks. According to CrowdStrike's 2025 Global Threat Report, 79% of attacks detected last year were malware-free, compared to 40% in 2019. However, Malware-as-a-Service tools like Lumma continue to attract buyers, allowing less sophisticated threat actors to access advanced capabilities
3
.Despite the successful takedown, authorities warn that Lumma remains a potent threat. Microsoft continues to monitor emerging variants of the malware, emphasizing the need for ongoing vigilance in the face of evolving cybersecurity challenges
3
.Summarized by
Navi
[2]
14 Jan 2026•Policy and Regulation

22 Sept 2026•Technology

30 May 2025•Technology

1
Technology

2
Policy and Regulation

3
Technology
