Lumma Stealer
Lumma Stealer とは何ですか?
Lumma StealerA subscription-priced Russian-speaking malware-as-a-service info-stealer that emerged in 2022 and became one of the top-three stealers worldwide by 2024, distributed primarily via ClickFix lures and crack sites.
Lumma Stealer (also called LummaC2) is a C-language Windows info-stealer first observed in mid-2022 and rented out as malware-as-a-service in Russian-speaking criminal forums. By 2024 it had become one of the dominant info-stealers worldwide alongside RedLine and StealC, having largely filled the vacuum left by RedLine and Raccoon takedowns. Capabilities are typical of the category: theft of browser cookies, saved passwords, autofill data, crypto-wallet files, Discord and Telegram tokens, Steam sessions, and arbitrary files matched against operator-supplied patterns. Lumma is widely distributed via ClickFix fake-CAPTCHA lures, malicious cracks and YouTube tutorials, malvertising, and SEO-poisoned download sites. The 2024–2025 operator added GenAI-powered command-and-control obfuscation and bundled a loader stage for follow-on payloads such as ransomware. In May 2025 Microsoft Digital Crimes Unit, the U.S. DOJ, Cloudflare, ESET and Europol jointly disrupted Lumma's infrastructure (Operation Endgame), seizing roughly 2,300 domains and disrupting the storefront, though the actor's panel and forks resurfaced within weeks.
● 例
- 01
A user clicks a fake reCAPTCHA, pastes the offered PowerShell into Run, and a Lumma loader stages the stealer that exfiltrates browser cookies within minutes.
- 02
Operation Endgame's May 2025 takedown sinkholes ~2,300 Lumma domains, briefly collapsing the storefront before clones return on bulletproof hosting.
● よくある質問
Lumma Stealer とは何ですか?
A subscription-priced Russian-speaking malware-as-a-service info-stealer that emerged in 2022 and became one of the top-three stealers worldwide by 2024, distributed primarily via ClickFix lures and crack sites. サイバーセキュリティの マルウェア カテゴリに属します。
Lumma Stealer とはどういう意味ですか?
A subscription-priced Russian-speaking malware-as-a-service info-stealer that emerged in 2022 and became one of the top-three stealers worldwide by 2024, distributed primarily via ClickFix lures and crack sites.
Lumma Stealer はどのように機能しますか?
Lumma Stealer (also called LummaC2) is a C-language Windows info-stealer first observed in mid-2022 and rented out as malware-as-a-service in Russian-speaking criminal forums. By 2024 it had become one of the dominant info-stealers worldwide alongside RedLine and StealC, having largely filled the vacuum left by RedLine and Raccoon takedowns. Capabilities are typical of the category: theft of browser cookies, saved passwords, autofill data, crypto-wallet files, Discord and Telegram tokens, Steam sessions, and arbitrary files matched against operator-supplied patterns. Lumma is widely distributed via ClickFix fake-CAPTCHA lures, malicious cracks and YouTube tutorials, malvertising, and SEO-poisoned download sites. The 2024–2025 operator added GenAI-powered command-and-control obfuscation and bundled a loader stage for follow-on payloads such as ransomware. In May 2025 Microsoft Digital Crimes Unit, the U.S. DOJ, Cloudflare, ESET and Europol jointly disrupted Lumma's infrastructure (Operation Endgame), seizing roughly 2,300 domains and disrupting the storefront, though the actor's panel and forks resurfaced within weeks.
Lumma Stealer からどのように防御しますか?
Lumma Stealer に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
Lumma Stealer の別名は何ですか?
一般的な別名: LummaC2, Lumma。
● 関連用語
- malware№ 591
インフォスティーラー
感染端末から認証情報、Cookie、トークン、暗号資産ウォレットなどの機密データを収集し、攻撃者へ持ち出すマルウェア。
- attacks№ 199
ClickFix Attack
A 2024-vintage social-engineering lure that displays a fake CAPTCHA, error dialog, or 'verify you're human' page instructing the victim to paste a pre-copied PowerShell command into Run, delivering info-stealers or loaders.
- malware№ 254
認証情報窃取マルウェア
感染システムやそのメモリからパスワード、ハッシュ、認証トークンを取り出すことに特化したマルウェア。
- malware№ 1014
RedLine Stealer
A subscription Windows info-stealer that dominated 2020–2023 cybercrime markets, harvesting browser secrets, crypto wallets, and FTP/VPN credentials; its infrastructure was disrupted by Operation Magnus in October 2024.
- malware№ 1329
Vidar Stealer
A long-running C++ Windows info-stealer derived from the older Arkei family, active since 2018 and still distributed in 2024–2025 via cracks, malvertising, and ClickFix lures.
- attacks№ 720
マルバタイジング
信頼されたウェブサイト上に表示される一見正規の広告を通じて、オンライン広告網からマルウェア・エクスプロイト・詐欺を配信する手口。
● 関連項目
- № 998Raccoon Stealer