Lumma Stealer, also known as LummaC2, is a Russian related infostealer that emerged as a MaaS (Malware as a Service) in 2022. Lumma quickly became one of the most popular stealers thanks to its various ways of distribution and the difficulty to detect the malware once it has infected the device.
In May of 2025, the stealer suffered a serious hit, where thousands of domains related to it were seized by Microsoft. However, this did not shut down the stealer for good, and it is still operational as of today.
Full Name: LummaC2
First Appearance: Dec 2022
Related Actor: Shamel (also named Lumma), Russia.
MaaS Subscription
Lumma offers several subscription, each building on the features of the previous one. They also offer server installation and 24/7 hour support.
Subscription plans:
| Experienced | Professional | Corporate |
|---|---|---|
| Download logs in bulk, by query | ||
| Can sort by parameters | ||
| Exclude empty logs | Unlimited filters | |
| Delete logs in bulk | ||
| Log quality and statistics available | ||
| Ability to add and remove browsers, paths, profiles and general depth and order of data collection | Less detectable | |
| Implements Heaven’s Gate | ||
| Ink builder | ||
| All improvments appear here before moving to the other subscriptions (if they do) | ||
| Unique builder, increasing anonimity | ||
| 250$/month | 500$/month | 1000$/month |
In case your monthly subscription ends, your old logs do not disappear. On top of that, once it is renewed, the logs during the period of your inactivity will be available.
Lumma – Stealer Evolution
LummaC2 originated on XSS in late 2022, by a threat actor known as ‘Shamel’, now going simply by ‘Lumma’.
While the first post on XSS publishing Lumma as a MaaS was published in December of 2022, posts by Shamel can be tracked to a few months before, showing warning signs.

A post by Shamel (Lumma) talking about decryption
LummaC2 Takedown – May 2025
See full article here
On the 15th of May, 2025, users have started to experience issues with the panels and the market domain of Lumma. Discussion on the main Lumma thread started, and rumors of an arrest started to spread


A post from the 16.05.2025 raising rumors of the shutdown of the servers
The last update by the official Lumma account was on the 19.05.2025. By then the servers were possibly already compromised, and this could be a message to throw off suspecting users until the opperation is complete properly. (valid for the 22.05.2025)
On the 21.05.2025, several news outlets published that a coordination of the US, EU and Microsoft stook down the Lumma infrastructure. A court order allowed Microsoft to block thousands of malicious domains that held up Lumma’s infrastructure, severing communication between the infected devices and the control panels.
The FBI also stated they are tracking and planning on taking down anyone who used the MaaS subscription. The sent out an official statment urging anybody responsible to come forward.
Discussion on the topic quickly rose, with users stating that the panel shows a ‘siezed by FBI’ message, as well as some users raising concerns of legal actions against them.

The message sent by the FBI in the Lumma TG chat

The takedown message displayed when attempting to access the control panel

A post by a concerned user regarding the chase after Lumma customers
On the 23rd of May, the Lumma admin finally released a statement on the official thread, claiming to regain access to the servers. However, the reputational damage has already been done, as many users seemed frustrated with the delayed response and the loss of logs.

Post made by Lumma regarding the takedown

Customers looking for alternatives
Lumma – Technical Capabilities
Programming Language: C++
Build Weight: 150-300KB
LummaC2 is updated every 2 hours.
Data Types Stolen
Operating Systems Targeted: Windows 7 x32 to Windows 11 x64.
CPU Targeted: ARM, x84, x64
Extensions:
- MetaMask 2) 1Password 3) Braavos 4) Agrent X 5) Coinhub 6) Leap Wallet 7) Safepal 8) LastPass 9) Ronin Wallet 10) Evernote 11) MultiversX Wallet 12) ForniterWallet 13) Fluvi Wallet 14) Glass Wallet 15) Morphis Wallet 16) XVerse Wallet 17) Compas Wallet 18) Havah Wallet 19) Sui Wallet 20) Venom Wallet 21) Trust Wallet 22) TronLink 23) OKX 24) Binance Chain Wallet 25) Yoroi 26) Nifty 27) Math 28) Coinbase 29) Guarda 30) EQUA 31) Jaxx Liberty 32) BitApp 33) iWlt 34) EnKrypt 35) Wombat 36) MEW CX 37) Guild 38) Saturn 39) NeoLine 40) Clover 41) Rabby 42) Martian 43) Bitwarden 44) Nami 45) Petra 46) ExodusWeb3 47) Sub 48) PolkadotJS 49) Talisman 50) CryptoCom 51) Liquality 52) Terra Station 53) Keplr 54) Sollet 55) Auro 56) Polymesh 57) ICONex 58) Nabox 59) KHC 60) Temple 61) TezBox 62) DAppPlay 63) BitClip 64) Steem Keychain 65) Nash Extension 66) Hycon Lite Client 67) ZilPay 68) Coin98 69) Authenticator 70) Cyano 71) Byone 72) OneKey 73) Leaf 74) Solflare 75) Magic Eden 76) Backpack 77) Authy 78) EOS Authenticator 79) GAuth Authenticator 80) Trezor Password Manager 81) Phantom 82) UniSat 83) Rainbow 84) Bitget Wallet 85) MetaMask Mozilla
Cold wallets:
- Ethereum 2) Exodus 3) Ledger Live 4) Atomic 5) Coinomi 6) Bitcoin core 7) Binance 8) JAXX New Version 9) Electrum-LTC 10) ElectronCash 11) Guarda 12) DashCore 13) Wasabi 14) Daedalus
Browsers:
- Chrome 2) Chrome Beta 3) Opera 4) Opera Neon 5) Opera GX Stable 6) Edge 7) Brave 8) EpicPrivacyBrowser 9) Vivaldi 10) Maxthon 11) Iridium 12) AVG Secure Browser 13) QQBrowser 14) 360Browser 15) ZiNiao Browser 16) CentBrowser 17) Chedot 18) CocCoc 19) Mozilla Firefox 20) Waterfox 21) Pale Moon
Applications:
- KeePass 2) 1Password 3) Bitwarden 4) NordPass 5) Telegram 6) FileZilla 7) TotalCommander 8) AnyClient 9) 3D-FTP 10) SmartFTP 11) FTPGetter 12) FTPbox 13) FTPInfo 14) FTPRush 15) FTP Commander Deluxe 16) FTP Manager Lite 17) Auto FTP Manager 18) OpenVPN 19) NordVPN 20) ProtonVPN 21) AnyDesk 22) Azure 23) Notes 24) Notezilla 25) TheBat 26) Pegasus 27) Mailbird 28) EmClient 29) Discord
2FA Extensions
Files: Low adaptive file grabber from the ‘documents’ folder.
Command & Control Server
The C2 center is web based and has server based encryption. The data is sent to it in chunks in order to increase response time.
The user can define the logs wanted directly from the C2 by creating queries. User can also filter logs by country, wallets, cookies and passwords.
The panel has a modern design available in two themes – light and dark. The main page offers brief statistics such as total number of logs, cypto and wallet amounts, map distribution and more.
My logs + Filter Section
Each log extracted by the build is identified by a set of factors such as time, IP, country, and several other filters that can be defined by the user. This section allows you to download the logs or delete them.
Log search is available by any of the filters above, which also allows for easier log sharing.
This is directly effected and effects the filters section where you can choose which fields to sort and filter by.
Builds Section
Allows you to control your different builds. It indicates last cleaning date and the size of each build, and allows you to name and tag your different builds in order to keep them organized.
Here you can also pick which server the build will work on (which they recommend to check for detection before choosing). Each build is different thanks to the built in morpher, and the average detection rate (knock) of the build is also presented.
Loader Section
There is a custom made, built in loader which is non-resident to the victim’s computer. This means it allows deployment of EXE/DLL/PS1 files without installing a permanent code on the computer itself. In order to execute this, a loaded file must be uploaded to hosting and a link must be inserted in the panel.
Config Section
This section allows you to configure the extensions, links, and paths your build will go into. This is also where you can dictate which files will be available to you – screenshots, virutal machines, and more. You can choose from preset configs or create your own.
Logs for Sale + Download logs + Workers + Passwords Section
This section allows purchase and sale of logs. You can also download your logs directly and archive them in the download logs section, or just the passwords in the passwords section.. Once you share your logs through a special link, you will get statistics about its view count in the workers section.
Log Quality + Share Statistics Section
Statistics about your logs, their quality, percentage of quality and removal of empty files for cleaner data.
These statistics can be shared to your audiance allowing them to ask for areas of improvment.
Utilities Section
A section monitoring the log signatures which allows you to make sure no one is changing the logs you distribute.
Protection from Bots Section
A section allowing you to review and complain about bots. If a bot has too many complaints, it is automatically banned. The bot list is checked manually periodically, even with no complaints.
Additional Features
Lumma utilized a proprietary morpher in the builder itself to mask it. It also rotates between 11 different servers as well as providing the option to connect a personal server.
Lumma creates its own Ink shortcuts in order to avoid detection.
The newer iterations of LummaC2 have embraced a modular design that allows attackers to swiftly add or modify capabilities. This flexibility means the malware can be tailored for specific targets or integrated as part of more complex, multi-stage attack campaigns.
Lumma – TTPs
Attack Vector
Delivery
LummaC2 originally distributed through fake CAPTCHA that came from phishing links or pop-up advertisements. The fake CAPTCHA asks the user to perform an .exe command which after several steps downloads a malicious HTML application to the computer.

Installation
The program downloaded is encrypted several times in order to abscure its true purpose, using hashed commands and executables. The hashing algorithem is called MurmurHash2.
Lumma rarely uses High-Level WinAPI. When it does need to directly interact with the operating system, it does so on the base level using assembly language, making it hard to read and detect.
Imagine you want a glass of water:
- Using WinAPI = You ask a waiter for water.
- Using syscalls in ASM = You go to the kitchen, find the pipe, and twist the valve yourself — with a wrench — while reading a plumbing manual.
A big thing about Lumma is that it is very direct, it does not do anything to the computer other then steal information, with no differentiation between the devices infected.
Once in the system, one of the first things the malware does is disable the Antimalware Scan Interface communication (AMSI) in order to remove antivirus detection. This operation is then checked again by multiple other commands to ensure the successful shutdown of the antivirus application. In case the antivirus is not shut down, the malware pipeline will collapse and will not install on the device.
Lumma also implements Heaven’s Gate technology in order to bypass security on x32 code.
Information Gathering
The process is very direct and fast. During the execution, the malware contacts the C2 panel in a one way manner- expecting no response. It does that several times, sending the ZIP stealer log file in chunks.
Each time it sends information back to the C2 panel, it does so in a specific information format containing file name, HWID, PID (Petition ID, how many times did this malware exfiltrate data) and LID (Lumma ID)

System – The first thing that Lumma gathers is the system information, stores in the ‘system.txt’ file, by executing a few windows commands:
- System Commands
- GetComputerNameA
- GetCurrentHwProfileA
- GetSystemMetrics
- GetSystemDefaultLocaleName
- cpuid
- GetPhysicallyInstalledSystemMemory
- MITRE ATT&CK
Files – Lumma classified an ‘important’ file as any .txt file that is under ‘userprofiles’, and fetches as deep as 2 directories.
Crypto – After stealing files and system information, it goes on to steal crypto wallets from Binance, Electrum and Ethereum (in this order). After this is the first compression of the file and the delivery to the C2 panel.
Browsers – After the first extraction, the stealer goes into the browsers and extracts all the relevant information, as well as 2FA and Crypto extensions.
MITRE ATT&CK
Malware ID: S1213 (https://attack.mitre.org/software/S1213/)
| Tactic | Technique ID | Technique Name | Use |
|---|---|---|---|
| C2 | T1071.001 | Application Layer Protocol: Web Protocols | Lumma uses HTTP/S for the command and control center |
| Collection | T1119 | Automated Collection | Lumma automatically collects various pieces of data |
| Persistance | T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder | Lumma creates registery keys to remain active |
| Collection | T1217 | Browser Information Discovery | Lumma identifies and gathers information from 2FA extensions on several browsers |
| Execution | T1059.001 | Command and Scripting Interpreter: PowerShell | Lumma uses PowerShell for user execution |
| Execution | T1059.006 | Command and Scripting Interpreter: Python | Lumma uses malicious Python scripts for execution |
| Execution | T1059.010 | Command and Scripting Interpreter: AutoHotKey | Lumma utilizes AutoIt scripts and executables |
| Credential Access | T1555.003 | Credentials from Password Stores: Credentials from Web Browsers | Lumma gathers credentials from multiple browsers |
| Collection | T1074.001 | Data Storage: Local Data Staging | Lumma configures a custom data directory for staging data |
| Defense Evansion | T1622 | Debugger Evasion | Lumma checks for debugger strings containing terms such as ‘dbg’, ‘debugger’ and ‘dnspy’ |
| Defense Evasion | T1140 | Deobfuscate/Decode Files or Information | Lumma uses x64 encoded content which is later decoded by PowerShell. |
| C2 | T1573.002 | Encrypted Channel: Asymmetric Cryptography | Lumma uses HTTP/S for the command and control center |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | Lumma exfiltrates collected data over existing HTTP/S channels |
| Defense Evasion | T1564.003 | Hide Artifacts: Hidden Window | Lumma uses features that prevent it from creating visible windows, allowing it to run without displaying a command |
| Defense Evasion | T1574.001 | Hijack Execution Flow: DLL | Lumma leverages legitimate applications to load malicious DLLs |
| Defense Evasion | T1562.001 | Impair Defense: Disable Tools | Lumma attempts to bypass antimalware scan interface by removing strings from memory commands |
| Defense Evasion | T1039.008 | Masquerading: Masquerade File Type | Lumma uses payloads that resemble legit file extensions |
| Defense Evasion | T1027.013 | Obfuscated Files or Information: Encrypted/Encoded File | Lumma obfuscates payloads |
| Initial Access | T1566.001 | Phishing: Spearphishing Attachment | Lumma delivers through phishing emails with malicious attachments |
| Initial Access | T1566.002 | Phishing: Spearphishing Link | Lumma delivers through phising emails containing malicious links |
| Defense Evasion | T1055.012 | Process Injection: Process Hollowing | Lumma uses process hollowing (using empty, spare processes) to inject a malicious payload |
| Defense Evasion | T1620 | Reflective Code Loading | Lumma uses reflective loading to load content directly from memory during execution |
| Collection | T1113 | Screen Capture | Lumma takes screenshots of the victim’s machine |
| Discovery | T1518.001 | Software Discovery: Security Software Discovery | Lumma detects antivirus processes |
| Persistence | T1176.001 | Software Extensions: Browser Extensions | Lumma installs a malicious extension to target different browsers |
| Credential Access | T1539 | Steal Web Session Cookies | Lumma harvests cookies from various browsers |
| Defense Evasion | T1553.002 | Subvert Trust Controls: Code Signing | Lumma uses a valid code signing certificate to appear legitimate |
| Initial Access | T1195 | Supply Chain Compromise | Lumma can be deliviered through cracked software |
| Defense Evasion | T1218.005 | System Binary Proxy Execution: Mshta | Lumma uses Mshta to execute additional content |
| Defense Evasion | T1218.015 | System Binary Proxy Execution: Electron Applications | Lumma uses Electron to disable sandboxing and avoid detection |
| Discovery | T1082 | System Information Discovery | Lumma gatheres system information from the victim machine |
| Execution | T1204.002 | User Execution: Malicious File | Lumma can distribute through fake CAPTCHA or executing malicious files in ZIPs/RARs |
| Defense Evasion | T1497.001 | Virtualization/Sandbox Evasion: System Checks | Lumma queries system resources to identify virtual environments. |
Lumma – Log Structure

Main compressed folder
The stealer log comes in a compressed folder
Device Folder
Each device has a dedicated folder following a specific naming format:
[Country Code]IP
Relevant files and folders
Each device folder contains several subfolders and txt files. It is important to note that not all the files contain all of the same subfiles.
The main relevant folders are highlighted in yellow. The potentially relevant files (relevant in case another file is missing) are highlighted in green.
Relevant information
Each of the files contains the following relevant information that should be collected:
System.txt –
“a .txt file with data from an infected PC, contains running processes, where your build was launched, screen size data, CPU, video card and other features. Useful for subsequent use for uploading videos to YouTube.”
Software.txt
All Passwords.txt
This file compiles all of the passwords found inside the browser folders. In case this file does not exist, check the browser folders for a passwords.txt file.
Cookies (Folder)
“Netscape format text, or JSON with authorization history on websites.”
This folder compiles all the cookies found inside the browser folders. All files in this folder are relevant. In case this folder does not exist, check the browser folders for a Cookies.txt file.
Browser Folder (chrome, edge, etc.)
Use this folder in case one of the previously mentioned files does not exist. This folder contains sub folders to each user on the browser and inside them txt files. Relevant files are marked in yellow and follow the same format as their respective overall files.
Additional files
-
- Autofills
- FileGrabber – files (usually .txt format) received from the current account and the “Documents” folder.
- FTP – is a server(s) that operates on the File Transfer Protocol and is designed to exchange files over the Internet or a local computer network.
- Steam – files for importing into a local folder for authorization in Steam.
- Wallets – files in .dat format, which are imported into wallets using the CTRL+R key combination and entering the %appdata% command, you can find the folder with the wallet (Binance, Exodus, Jaxx Wallet and others).
- Screenshot – a .jpg file, a regular screenshot from the account of an infected PC.