Malware
Lumma Stealer explained: credential theft, detection and safe response
What Lumma Stealer is, how it can target browser credentials and sessions, what a detection means, and safe steps after a suspected infostealer alert.

Lumma Stealer is a Windows information-stealing malware family. It is also known as LummaC2 and has been offered as malware-as-a-service. Reports describe it collecting information from browsers and applications, including stored credentials, session cookies, multifactor-authentication-related data, system information and cryptocurrency-wallet data. A report about the Lumma family is not proof that this reader's device is infected. A specific security alert, file, endpoint event or forensic finding is needed to assess an individual device. MITRE ATT&CK tracks Lumma Stealer as software S1213 and says it has been in use since at least 2022. That record documents reported capabilities and techniques; it does not establish current prevalence, a current campaign, or an infection on any particular computer. [MITRE S1213, private evidence source]
What is Lumma Stealer?
Lumma Stealer is an infostealer: malware designed to collect valuable information from a device and send it to an operator. Microsoft describes Lumma, or LummaC2, as a malware-as-a-service offering used by multiple financially motivated threat actors. A service model lets affiliates obtain or configure the malware and operate their own campaigns rather than writing every component themselves. [Microsoft Threat Intelligence, private evidence source]
This is different from saying that Lumma is a computer virus in the narrow sense. The family is classified as information-stealing malware. It may be delivered inside a fake application, archive, attachment, web page or social-engineering flow, but its defining purpose in the cited records is data theft. For a broader explanation of malware categories, see the verified CYBERoinfo malware hub and infostealer malware guide.
What credentials can Lumma Stealer target?
Reported Lumma capabilities include collecting data from web browsers and applications. Depending on the variant, campaign and configuration, that can include:
The exact data collected is not identical in every sample. A family description is a capability report, not a finding that every listed data type was taken from every victim. CISA and the FBI’s May 2025 advisory also describe LummaC2 as capable of exfiltrating personally identifiable information, financial credentials, wallet data, browser extensions and MFA-related details. [FBI/CISA AA25-141B, private evidence source]
A stolen password is not the only concern. A session cookie or other active session material can sometimes let an attacker access an account without asking for the password again. That is why changing a password alone is not a guaranteed recovery after a suspected infostealer incident. On a known-clean device, change affected passwords, revoke other sessions and review account security events. Re-enrol or rotate MFA where the provider supports it, and follow the account provider’s recovery process. Do not paste passwords, recovery codes, seed phrases or wallet details into this page or into an unsolicited support form.
- saved usernames, passwords and other browser-stored credentials;
- browser cookies and other web-session material;
- browser extensions, including information associated with some multifactor-authentication extensions;
- personal, system and financial information; and
- cryptocurrency-wallet data.
How is Lumma Stealer reported to reach a device?
Official reporting describes several delivery patterns. The specific path varies by campaign and date, so these examples should not be treated as a complete list or as proof of a current campaign.
These descriptions explain how a reported family has been delivered. They do not mean that seeing a malicious advertisement, fake CAPTCHA or suspicious email proves Lumma executed. Execution, detection telemetry or forensic evidence is needed to establish that.
- Phishing: an attachment or link may imitate a familiar service and lead to a malicious file or site.
- Malvertising and lookalike downloads: a poisoned advertisement or search result may imitate a browser, utility or other software download.
- Trojanized or cracked software: a modified installer may bundle the stealer with software the user expected to obtain.
- Compromised websites: injected scripts or redirects may lead to a payload or a deceptive prompt.
- Fake CAPTCHA and “verification” prompts: some campaigns have instructed users to open the Windows Run dialog and paste clipboard contents. FBI/CISA and Microsoft describe this as a social-engineering path that can run an encoded PowerShell command. Do not follow instructions that ask a CAPTCHA to make you open Run, paste a command or execute text.
- Another malware family: Microsoft has reported observing other malware loaders deliver Lumma as an additional payload.
What does a Lumma Stealer detection mean?
A detection name such as Behavior:Win64/LummaStealer.AB is a security product’s classification of a file or observed behavior. Microsoft’s threat encyclopedia says Microsoft Defender detects and removes that named threat, while also warning that infections can leave remnants and system changes. The detection should therefore be taken seriously, but its meaning still depends on the event details: whether the item was blocked before execution, quarantined, allowed, detected in memory, or found during a later scan.
A family name in a threat report has a different evidentiary value. MITRE S1213, a Microsoft research article, a CISA advisory or a news report can establish that Lumma is a documented family and describe reported behavior. None of those sources, by itself, confirms that this reader’s computer or account was affected.
If an alert appeared on your device, record the product name, detection name, timestamp, device and action taken. Use the product’s official console or support documentation rather than an unsolicited phone number, pop-up or social-media account. Do not upload private logs, credentials or wallet material to an unknown “removal” service.
What should you do after a suspected Lumma alert?
Use this checklist as a cautious first response. Organizations should use their incident-response process and preserve evidence before making changes that could destroy useful telemetry.
For a short, general sequence, see the verified CYBERoinfo incident first-hour checklist, strong account checklist and personal device guide. Those resources do not replace the instructions of an employer, security provider, bank or account service.
- Stop using the suspected device for sensitive sign-ins. Do not enter passwords, payment details, recovery codes or wallet secrets on it while its status is uncertain.
- Record the alert. Save the detection name, path or alert identifier, time, device and whether the security product blocked or quarantined it. Do not execute the detected file to “test” it.
- Isolate according to your context. For a managed work device, contact the security or IT team and follow its instructions. For a personal device, disconnecting it from networks can limit further communication, but do not take steps that could destroy evidence if a professional is investigating.
- Use a known-clean device for account protection. Change passwords for accounts that were used on the suspected device, beginning with email, identity, financial and administrator accounts. Use unique passwords or passkeys and do not reuse the old password.
- Revoke access beyond the password. Sign out other sessions, review active devices and connected applications, rotate recovery methods where appropriate, and re-enrol MFA if the provider advises it. Check for new forwarding rules, recovery addresses, app passwords or unfamiliar account changes.
- Run the security provider’s current remediation process. Update security software, apply operating-system and browser updates, and follow official full-scan or offline-scan guidance. If the alert persists, a qualified technician or organizational incident responder should assess the device; do not rely on a marketing claim of guaranteed removal.
- Watch accounts after containment. Review sign-in alerts, password-reset notices, email rules, payment activity and other high-value account events. Report suspected fraud through the relevant bank, service provider or law-enforcement channel.
Does changing passwords remove the risk?
No. Password changes are important, but they do not prove that an infostealer incident is fully resolved. A stealer may have collected cookies, tokens, MFA-related information, browser data or account-recovery details. A device may also retain files or changes after a security product removes a detected component. Microsoft’s threat encyclopedia specifically notes that remnants and system changes can remain after automatic removal.
Use a clean device to change affected passwords, revoke sessions and review account changes. Keep monitoring for delayed misuse. If a work, school or financial account was involved, notify the responsible security or fraud team promptly. If a wallet or recovery secret may have been exposed, use the wallet provider’s official compromise procedure; do not share the secret with anyone offering to “check” or “recover” it.
What did the 2025 Lumma disruption establish?
On 21 May 2025, Microsoft and Europol reported a coordinated disruption of Lumma infrastructure. Microsoft said it identified more than 394,000 Windows computers globally infected by Lumma between 16 March and 16 May 2025, and described domain seizures, sinkholing and efforts to cut communications. Europol reported the same measurement and explained its coordination role. These are official reports about a defined observation window and operation. They are not a current global prevalence estimate, a ranking promise, or evidence about this reader’s device.
The FBI/CISA advisory published on 21 May 2025 said the associated indicators related to infections observed from November 2023 through May 2025, with activity observed as recently as May 2025. Those dates are important limits. They should not be rewritten as proof of activity today or used to imply that an old indicator is still malicious without current validation.
Frequently asked questions
Question: Is Lumma Stealer still on my computer if Defender detected it?
Not necessarily. A blocked or quarantined item may mean execution was prevented, while a detection after execution may require a broader assessment. Preserve the alert details, update security software and follow the product’s current remediation guidance. If sensitive accounts were used on the device, protect them from a known-clean device even if removal appears successful.
Question: Does a Lumma report mean my passwords were stolen?
No report can establish that without device and account evidence. The family is capable of targeting credentials and session data, so a confirmed execution or credible endpoint finding should be treated as a possible exposure. Change passwords and revoke sessions from a clean device, but do not claim that every credential was stolen or that a reset guarantees safety.
Question: Is Lumma a virus?
Lumma is more accurately described here as an infostealer malware family, not a narrow file-infecting virus. The useful question is what the alert or investigation found and what information may have been exposed.
Question: Should I send someone my password or wallet phrase so they can check it?
No. Never send passwords, one-time codes, recovery codes, private keys or seed phrases to this page, a stranger or an unsolicited “support” contact. Use the official account, bank, exchange or wallet-provider recovery channel and enter secrets only into the service’s verified interface.
Question: Can this page tell whether my device is infected?
No. This article explains the family and safe next steps. It cannot inspect a device or confirm an individual infection. A trustworthy determination requires the relevant security-product event, endpoint telemetry or professional forensic review.
Evidence limits and ownership
This page describes reported Lumma Stealer behavior using MITRE ATT&CK S1213 and official Microsoft, Europol and FBI/CISA material. Vendor and government reports use different observation methods and dates. Capabilities can vary by sample and operator. No statement here is a guarantee of removal, account safety, current activity or future prevalence.
The proposed page owns the query cluster around what Lumma Stealer is, how its credential theft is reported, and what a Lumma detection means. It should not become a generic malware taxonomy page, a current-threat dashboard or a wallet-recovery page. The verified site’s broader infostealer credential-markets threat page may be a related destination, but this page should retain the Lumma-specific detection-and-response intent. The future named-malware directory can link here only after this route is separately approved and published.
---
Decision checklist
- Stop using the suspected device for sensitive sign-ins. Do not enter passwords, payment details, recovery codes or wallet secrets on it while its status is uncertain.
- Record the alert. Save the detection name, path or alert identifier, time, device and whether the security product blocked or quarantined it. Do not execute the detected file to “test” it.
- Isolate according to your context. For a managed work device, contact the security or IT team and follow its instructions. For a personal device, disconnecting it from networks can limit further communication, but do not take steps that could destroy evidence if a professional is investigating.
- Use a known-clean device for account protection. Change passwords for accounts that were used on the suspected device, beginning with email, identity, financial and administrator accounts. Use unique passwords or passkeys and do not reuse the old password.
- Revoke access beyond the password. Sign out other sessions, review active devices and connected applications, rotate recovery methods where appropriate, and re-enrol MFA if the provider advises it. Check for new forwarding rules, recovery addresses, app passwords or unfamiliar account changes.
- Run the security provider’s current remediation process. Update security software, apply operating-system and browser updates, and follow official full-scan or offline-scan guidance. If the alert persists, a qualified technician or organizational incident responder should assess the device; do not rely on a marketing claim of guaranteed removal.
- Watch accounts after containment. Review sign-in alerts, password-reset notices, email rules, payment activity and other high-value account events. Report suspected fraud through the relevant bank, service provider or law-enforcement channel.
Limitations
- An alert or family name alone does not confirm an infection or data theft on a particular device.
- Historical activity and vendor capability descriptions are not proof of a present-day outbreak or specific sample behavior.
- A scan or infrastructure disruption cannot guarantee that every related threat was removed.
- This educational article is not personalized incident-response or a device-specific diagnosis.
Evidence sources
- MITRE ATT&CK — Lumma Stealer
- Microsoft — Lumma Stealer: Breaking down the delivery techniques and capabilities of a prolific infostealer
- Microsoft — Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool
- Europol — Europol and Microsoft disrupt world’s largest infostealer Lumma
- CISA — Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
- Microsoft — Behavior:Win64/LummaStealer.AB