ATT&CKSoftwareLumma Stealer

Lumma Stealer

S1213

Malware.View on attack.mitre.org

About this malware

Lumma Stealer is an information stealer malware family in use since at least 2022. Lumma Stealer is a Malware as a Service (MaaS) where captured data has been sold in criminal markets to Initial Access Brokers.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1027
Obfuscated Files or Information

Lumma Stealer has used SmartAssembly to obfuscate .NET payloads.

T1027.013
Encrypted/Encoded File

Lumma Stealer has used AES-encrypted payloads contained within PowerShell scripts.

T1036.008
Masquerade File Type

Lumma Stealer has used payloads that resemble benign file extensions such as .mp3, .accdb, and .pub, though the files contained malicious JavaScript content.

T1041
Exfiltration Over C2 Channel

Lumma Stealer has exfiltrated collected data over existing HTTP and HTTPS C2 channels.

T1055.012
Process Hollowing

Lumma Stealer has used process hollowing leveraging a legitimate program such as “BitLockerToGo.exe” to inject a malicious payload.

T1059.001
PowerShell

Lumma Stealer has used PowerShell for initial user execution and other fuctions.

T1059.006
Python

Lumma Stealer has used malicious Python scripts to execute payloads.

T1059.010
AutoHotKey & AutoIT

Lumma Stealer has utilized AutoIt malware scripts and AutoIt executables.

T1071.001
Web Protocols

Lumma Stealer has used HTTP and HTTP for command and control communication.

T1074.001
Local Data Staging

Lumma Stealer has configured a custom user data directory such as a folder within `%USERPROFILE%\AppData\Roaming` for staging data.

T1082
System Information Discovery

Lumma Stealer has gathered various system information from victim machines.

T1113
Screen Capture

Lumma Stealer has taken screenshots of victim machines.

T1119
Automated Collection

Lumma Stealer has automated collection of various information including cryptocurrency wallet details.

T1140
Deobfuscate/Decode Files or Information

Lumma Stealer has used Base64-encoded content during execution, decoded via PowerShell.

T1176.001
Browser Extensions

Lumma Stealer has installed a malicious browser extension to target Google Chrome, Microsoft Edge, Opera and Brave browsers for the purpose of stealing data.

View all 35 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. Cybereason LumaStealer Undated Open source
    Cybereaon Security Services Team. (n.d.). Your Data Is Under New Lummanagement: The Rise of LummaStealer. Retrieved March 22, 2025.
  2. Fortinet LummaStealer 2024 Open source
    Cara Lin, Fortinet. (2024, January 8). Deceptive Cracked Software Spreads Lumma Variant on YouTube. Retrieved March 22, 2025.
  3. Netskope LummaStealer 2025 Open source
    Leandro Fróes, Netskope. (2025, January 23). Lumma Stealer: Fake CAPTCHAs & New Techniques to Evade Detection. Retrieved March 22, 2025.
  4. Qualys LummaStealer 2024 Open source
    Vishwajeet Kumar, Qualys. (2024, October 20). Unmasking Lumma Stealer: Analyzing Deceptive Tactics with Fake CAPTCHA. Retrieved March 22, 2025.
  5. TrendMicro LummaStealer 2025 Open source
    Buddy Tancio, Fe Cureg, and Jovit Samaniego, Trend Micro. (2025, January 30). Lumma Stealer’s GitHub-Based Delivery Explored via Managed Detection and Response. Retrieved March 22, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.