Lumma Stealer Takedown Reveals Sprawling Operation
1 min read
Photo credit: Lucas Andrade via Pexels. Article by Tara Seals. Dark Reading – May 21, 2025.
The Lumma Stealer malware operation has gone dark, thanks to a coordinated law-enforcement effort that seized five Internet domains that its operators use to distribute the data-thieving binary to cybercriminal customers and affiliates. In addition to the five Internet domains that hosted the user panels for malware-as-a-service clients, Microsoft separately led a takedown of 2,300 domains that hosted other parts of the Lumma Stealer infrastructure, sinkholing their traffic for analysis. […]