Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Microsoft has destroyed the world's largest information thief. The Lumma Stealer project was created by a Russian IT worker: details of the operation

Europol’s European Cybercrime Center, together with Microsoft, has shut down Lumma Stealer («Lumma»), the world’s largest data theft threat. Here are the details.

Leave a comment
Microsoft has destroyed the world's largest information thief. The Lumma Stealer project was created by a Russian IT worker: details of the operation

Europol’s European Cybercrime Center, together with Microsoft, has shut down Lumma Stealer («Lumma»), the world’s largest data theft threat. Here are the details.

This joint operation was directed against a complex ecosystem that allowed criminals to massively exploit stolen information.

Between March 16 and May 16, 2025, Microsoft detected over 394,000 Windows computers worldwide infected with the Lumma malware.

This week, in a coordinated follow-up operation, Microsoft’s Digital Crime Unit (DCU), Europol, European and Japanese law enforcement agencies, as well as ESET, Bitsight, Lumen, Cloudflare, CleanDNS, and GMO Registry compromised Lumma’s technical infrastructure, cutting off communication between the malicious tool and its victims. In addition, more than 1,300 domains that were removed or transferred to Microsoft will be redirected to Microsoft’s dedicated servers, which allow us to securely intercept requests from infected systems, obtain technical information about the attacks, and identify the types of data stolen.

Microsoft warns that Lumma may be relaunched under a new name, or another infostyler may take its place.

What is Lumma?

Lumma, the world’s largest data stealer, was a sophisticated tool that allowed cybercriminals to harvest sensitive data from compromised devices en masse. The stolen credentials, financial data, and personal information were collected and sold through a dedicated marketplace, making Lumma a central tool for identity theft and fraud worldwide.

The Lumma Marketplace operated as a hub for buying and selling malware, giving criminals convenient access to advanced data-stealing capabilities. Its widespread use and accessibility made it a top choice for cybercriminals looking to exploit personal and financial data.

Russian roots

Lumma’s developer is a Russian who goes by the pseudonym Shamel. In November 2023, in an interview with researcher «g0njxa», Shamel reported that he had about 400 active customers. He created an entire Lumma brand, with a logo in the form of a bird, symbolizing «peace and ease», and the slogan: «With us it is easy to earn money.»

According to Steven Masada, deputy general counsel of Microsoft’s Digital Crimes Division, Lumma was a typical example of Malware-as-a-Service. Since 2022, it has been sold through underground Russian-language forums, as well as through Telegram. Buyers could customize their own versions: change the config, encrypt the code, track the collected data through a convenient admin panel. Lumma disguised itself as legitimate services, in particular, Booking.com, and spread through phishing emails and advertisements with embedded malicious code.

Researchers at Cato Networks said in a report published Wednesday that Lumma played a role in a February campaign that used Tigris and Oracle object storage services to host malicious websites.

«Attackers love credential theft because it allows them to target less secure personal devices that store corporate credentials and tokens,» said Christopher Russo, principal threat researcher at Palo Alto Networks’ Unit 42. «Primary access brokering is big business, allowing attackers to harvest credentials on a large scale with minimal risk.»

Lumma has also been linked to the notorious cybercrime group Scattered Spider.

An algorithm solved everything: Microsoft fired an employee with 25 years of experience on his birthday
An algorithm solved everything: Microsoft fired an employee with 25 years of experience on his birthday
On the topic
An algorithm solved everything: Microsoft fired an employee with 25 years of experience on his birthday
Microsoft adds Grok Mask to Azure despite AI's controversial behavior
Microsoft adds Grok Mask to Azure despite AI’s controversial behavior
On the topic
Microsoft adds Grok Mask to Azure despite AI’s controversial behavior
Hackers have leaked a trove of data from Spider-Man developer Insomniac Games. They revealed the studio's release schedule through 2030 and showed off Wolverine gameplay.
Hackers have released a trove of data from Spider-Man developer Insomniac Games. They revealed the studio’s release schedule through 2030 and showed off Wolverine gameplay.
On the topic
Hackers have released a trove of data from Spider-Man developer Insomniac Games. They revealed the studio’s release schedule through 2030 and showed off Wolverine gameplay.
Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram
Also Read
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
Microsft опубліковала аналіз кібервійни в Україні та розкрила, які групи хакерів пов’язані з ФСБ, ГРУ
Microsft опубліковала аналіз кібервійни в Україні та розкрила, які групи хакерів пов’язані з ФСБ, ГРУ
Microsft опубліковала аналіз кібервійни в Україні та розкрила, які групи хакерів пов’язані з ФСБ, ГРУ
Meta, Microsoft та інші великі компанії об'єдналися задля створення стандартів для метавсесвітів
Meta, Microsoft та інші великі компанії об'єдналися задля створення стандартів для метавсесвітів
Meta, Microsoft та інші великі компанії об'єдналися задля створення стандартів для метавсесвітів

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.