Malware
Lumma Stealer
- First Reported
- Apr 15, 2026
- Latest Reported
- Jun 24, 2026
Reported Context (2)
- A year ago, ESET Research was part of two major operations that disrupted some of the leading cybercriminal operations at the time, Lumma Stealer and Danabot. ESET Details Its Role in Operation Endgame Disruption of Amadey and Stealc
- example involved infrastructure hosted on REG.RU, where the IP 89.111.170[.]100 was linked to a Lumma Stealer malware campaign documented by CTM360. The operation abused Google Groups and Google-hosted Hunt.io Maps More Than 1,250 C2 Servers Across 165 Russian Providers
CVE (1)
Malware (16)
Threat Actors (5)
MITRE ATT&CK (51)
Vendors (19)
Products (6)
Tools (12)
Industries (2)
Countries (10)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.