HomeYoutubeInfo-stealer Lumma returns after being "struck" by authorities

Info-stealer Lumma returns after being “struck down” by authorities

Despite a major crackdown by international law enforcement agencies in May, the info-stealing malware Lumma is making a comeback. The Malware-as-a-Service (MaaS) platform , known for its ability to steal sensitive user information, appears to have made a near-full comeback.

Authorities were able to seize more than 2,300 domains and parts of Lumma’s infrastructure, causing a temporary shutdown of its operations. However, according to new findings from Trend Micro, Lumma’s operators not only survived the blow, but have re-established their infrastructure and continue to operate through new distribution channels.

See also: Rhadamanthys Infostealer leverages the ClickFix technique

Digital Resilience: Lumma 's infrastructure rebuilt

Although the authorities' initial attack targeted the heart of Lumma's infrastructure, its administrators stated almost immediately on well-known underground forums, such as XSS, that the central server was not significantly affected, which allowed the network to be restored.

 info-stealer Lumma malware

A few weeks later, Trend Micro recorded clear signs of rebuilding and reactivation, with Lumma’s infrastructure operating much as it did before the seizure. The platform is now avoiding services like Cloudflare, opting for alternative providers like Russia’s Selectel, to limit the possibility of future takedowns.

Distribution Methods: Lumma attacks from everywhere

Lumma Stealer continues to evolve its strategy, leveraging multiple and difficult-to-detect distribution channels:

  1. Fake Cracks & Keygens
    Through malvertising and manipulated search results, fake software is promoted. Victims are directed to websites that detect their system characteristics via Traffic Direction Systems (TDS) before triggering the Lumma.
  2. ClickFix Attacks
    Compromised websites display fake CAPTCHAs that trick the user into executing PowerShell commands, aiming to load malicious code directly into memory, bypassing antivirus and other security tools.
  3. GitHub
    Attackers create GitHub repositories with deceptive content, such as cheats for video games. The files host names like “TempSpoofer.exe” and contain Lumma payloads either as executables or ZIP files.
  4. YouTube & Facebook Manipulation
    : Fake posts and videos promote cracked software. Links lead to pages that appear legitimate, but host the info-stealer malware Lumma.

See also: Hackers exploit Shellter tool to develop infostealer

Info-stealer Lumma returns after being "struck" by authorities

The law enforcement impasse

The return of the Lumma Stealer demonstrates a harsh fact: Law enforcement crackdowns , no matter how massive, are not enough without arrests or indictments . The “snakehead” remains free and capable of rapidly re-establishing itself.

MaaS businesses like Lumma are extremely profitable, and their operators view regulatory interventions as temporary setbacks. “Malware as a service” continues to operate as a fully-fledged business model, with marketing, support, and active user communities.

Malware doesn't "die" – it mutates

The Lumma Stealer phenomenon is a prime example of the resilience of cybercrime . Until the perpetrators are identified and apprehended , crackdowns cannot provide a long-term solution.

See also: INTERPOL removes 20,000+ IPs linked to info-stealer

For businesses, IT teams, and security professionals, the answer cannot be just defensive. It requires a proactive approach, constant monitoring, user education, and rapid response to new attack methods.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS