Global Crackdown: FBI and Europol Shatter Lumma Stealer Network Behind 10 Million Infections


# Global Law Enforcement Disrupts Massive Lumma Stealer Operation

In a significant cybersecurity operation, international law enforcement agencies and private sector companies have successfully disrupted the Lumma Stealer malware network, seizing 2,300 domains that served as command-and-control (C2) infrastructure for the widespread information-stealing operation.

## Massive Scale of the Threat

Lumma Stealer, active since late 2022, has infected approximately 10 million Windows computers worldwide according to FBI estimates. Microsoft identified over 394,000 infected Windows systems globally between March and May 2025 alone. The malware has been used in at least 1.7 million instances to steal sensitive information including:

– Browser data
– Autofill information
– Login credentials
– Cryptocurrency seed phrases

Europol has described Lumma as the “world’s most significant infostealer threat.”

## Coordinated Takedown

The operation targeted five critical domains that served as login panels for Lumma’s administrators and customers, effectively cutting communication between the malware and victim computers. Microsoft’s Digital Crimes Unit collaborated with ESET, BitSight, Lumen, Cloudflare, CleanDNS, and GMO Registry to dismantle the malware’s infrastructure.

## Russian Origins and Business Model

According to Steven Masada of Microsoft’s DCU, “The primary developer of Lumma is based in Russia and goes by the internet alias ‘Shamel’.” The malware operates under a subscription-based malware-as-a-service (MaaS) model with tiered pricing:

– Basic plans: $250-$1,000
– Premium access: Up to $20,000 (includes source code and resale rights)

Higher-tier subscriptions offer advanced features like custom data collection, evasion tools, and early access to new capabilities.

## Sophisticated Distribution and Infrastructure

Lumma employs multiple distribution methods including phishing, malvertising, drive-by downloads, and the increasingly popular “ClickFix” technique. Recent campaigns have abused legitimate cloud services like Tigris Object Storage, Oracle Cloud Infrastructure, and Scaleway Object Storage to host fake reCAPTCHA pages that deliver the malware.

The stealer uses a multi-tiered C2 infrastructure with frequently changing domains and fallback mechanisms through Steam profiles and Telegram channels. Its code is heavily obfuscated with advanced protection techniques to evade analysis.

## Market Impact

The operation has significantly disrupted the cybercriminal ecosystem around Lumma. Before the takedown, researchers observed over 21,000 market listings selling Lumma Stealer logs between April and June 2024—a 71.7% increase from the same period in 2023.

While this operation has dealt a major blow to Lumma’s operations, security experts caution that the threat actors will likely adapt their tactics and attempt to rebuild their infrastructure.

## Future Outlook

Interestingly, in a January 2025 interview, Lumma’s developer indicated plans to cease operations by fall, stating: “We have done a lot of work over two years to achieve what we have now. We are proud of this. It has become a part of our daily life for us, and not just work.”

Share This Article