Global Takedown: 394,000 Infected PCs Freed as Authorities Crush Lumma Infostealer Network


# Global Operation Dismantles Lumma Malware Infrastructure

A major coordinated disruption operation against the Lumma malware-as-a-service (MaaS) information stealer has successfully seized thousands of domains and critical infrastructure components worldwide. The operation, conducted in May 2025, brought together multiple technology companies and law enforcement agencies in a comprehensive takedown effort.

Microsoft led the charge by seizing approximately 2,300 domains through legal action on May 13, while the Department of Justice simultaneously disrupted marketplaces where the malware was being rented to cybercriminals. Europol’s European Cybercrime Center and Japan’s Cybercrime Control Center provided additional support by targeting Lumma’s infrastructure in their respective regions.

“Between March 16, 2025, and May 16, 2025, Microsoft identified over 394,000 Windows computers globally infected by the Lumma malware,” said Steven Masada, Assistant General Counsel of Microsoft’s Digital Crimes Unit. “Working with law enforcement and industry partners, we have severed communications between the malicious tool and victims.”

The operation involved numerous technology partners including Cloudflare, ESET, CleanDNS, Bitsight, Lumen, GMO Registry, and global law firm Orrick. Cloudflare reported that Lumma had been abusing their services to hide server IP addresses used for collecting stolen data. Despite initial countermeasures, the malware evolved to bypass security controls, forcing Cloudflare to implement additional protections.

## What is Lumma Malware?

Lumma (also known as LummaC2) is a sophisticated information stealer targeting both Windows and macOS systems. Cybercriminals can rent this malware for between $250 and $1,000, gaining access to advanced evasion and data theft capabilities. The malware is typically distributed through GitHub comments, fake deepfake sites, and malvertising campaigns.

Once installed, Lumma steals sensitive data including:
– Cryptocurrency wallet information
– Browser cookies and credentials
– Passwords and credit card details
– Browsing history from Chrome, Edge, Firefox, and other browsers

First appearing on cybercrime forums in December 2022, Lumma quickly gained popularity among cybercriminals. According to IBM X-Force’s 2025 threat intelligence report, there has been a 12% increase in infostealer credentials for sale on the dark web over the past year, with Lumma being the most prevalent.

The malware has been linked to high-profile breaches at organizations including PowerSchool, HotTopic, CircleCI, and Snowflake. In response to the ongoing threat, the FBI and CISA have released a joint advisory detailing indicators of compromise and known tactics associated with Lumma malware deployments.

Share This Article