Malware

Lumma Stealer

Also known as: LummaC2 Stealer

Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell.

Indicators of Compromise 19

MITRE ATT&CK TTPs 6

Source Articles

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
A malicious Visual Studio Code extension named 'solidity-pro' has been identified as stealing cryptocurrency wallets, API keys, and credentials from developers. The threat delivers a browser wallet and credential stealer that exfiltrates sensitive data such as mnemonic phrases, SSH keys, GitHub tokens, AWS keys, and Telegram bot tokens via Telegram bots. The malware uses heavy obfuscation, delayed activation, and clean intermediate versions to evade detection by static scanners and sandbox environments.
hacker-news ·3w ago
EU sanctions Russian GRU military hackers over cyberattacks
The European Union and the United Kingdom have jointly imposed sanctions on Russian individuals and entities linked to state-sponsored cyberattacks. The targeted groups include GRU officers, FSB-affiliated hackers such as the Turla group, and cybercriminals involved in operations like the Lumma Stealer malware. These actors are accused of conducting cyberespionage, targeting critical infrastructure across Europe, and supporting disinformation campaigns. The sanctions follow a series of attacks on energy grids and government institutions, including failed attempts to disrupt Poland's power infrastructure.
bleeping-computer ·1mo ago
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
In April 2026, a financially motivated campaign distributed the Vidar stealer and XMRig cryptocurrency miner via malvertising, targeting users searching for cracked software. The attackers used password-protected archives with fake code signing certificates to evade detection and deliver payloads. The malware employed file inflation, DLL sideloading, and AMSI bypass techniques to avoid sandbox analysis and security controls. Victims were primarily located in the U.S. and EU, with data exfiltrated to C2 servers and Monero mining initiated through a configured pool.
unit42 ·1mo ago