Ad Banner
Advertisement by Open Privilege

Microsoft sues over Lumma Malware

Image Credits: UnsplashImage Credits: Unsplash
  • Microsoft has filed a legal suit and, alongside international law enforcement, disrupted operations of Lumma Stealer, a malware that compromised nearly 400,000 Windows devices globally in just two months.
  • Lumma Stealer functioned as malware-as-a-service, allowing cybercriminals to steal sensitive data—including passwords, credit card numbers, and cryptocurrency wallets—for as little as $250/month.
  • Over 2,300 malicious domains were seized, and global agencies including Europol and the FBI are continuing investigations, marking a significant blow to cybercriminal infrastructure.

[WORLD] Microsoft's Digital Crimes Unit has initiated legal proceedings against the Lumma Stealer malware, a sophisticated information-stealing tool that has compromised over 394,000 Windows computers globally between March 16 and May 16, 2025. This malware targets sensitive data such as passwords, credit card information, and cryptocurrency wallet credentials. In collaboration with the U.S. Department of Justice and Europol, Microsoft has successfully disrupted Lumma's operations by seizing over 2,300 malicious domains and redirecting them to secure servers. The FBI's Dallas Field Office is actively investigating the incident.

Lumma Stealer, also known as LummaC2, operates on a malware-as-a-service (MaaS) model, allowing cybercriminals to rent the tool for as little as $250 per month. Its primary function is to extract sensitive information from web browsers and applications, including credentials, cookies, and cryptocurrency wallet data. The malware has been distributed through various channels, such as fake CAPTCHA pages, cracked software, and phishing emails targeting platforms like GitHub and Discord.

Security analysts note that Lumma Stealer’s development appears to be highly professional, with frequent code updates and an active support community within underground forums. These forums often include user guides and troubleshooting assistance, indicating a robust commercial ecosystem that mimics legitimate software services. This level of sophistication has made it easier for lower-skilled threat actors to launch high-impact cyberattacks without developing malware from scratch.

In an alarming development, cybersecurity researchers discovered that Lumma Stealer has incorporated evasion techniques designed to bypass advanced endpoint protection. These include sandbox detection, process hollowing, and encrypted command-and-control communications that hinder traditional detection methods. Such capabilities make it particularly dangerous for enterprise environments where persistent threats can remain undetected for extended periods.

Global Impact and Response

Between March and May 2025, Lumma Stealer's infections spanned multiple industries, including healthcare, banking, and government sectors. Notably, U.S. State, Local, Tribal, and Territorial (SLTT) government organizations were among the affected entities. The malware's ability to bypass security measures and its widespread use in phishing attacks have made it a significant threat to cybersecurity.

Law enforcement officials have indicated that the takedown operation, dubbed “Operation Smart Shield,” was the result of months-long international cooperation. Europol, in coordination with cybersecurity firms and intelligence agencies, tracked the infrastructure supporting Lumma Stealer and coordinated simultaneous domain seizures across multiple jurisdictions. The effort marks one of the most extensive public-private partnerships targeting cybercrime to date.

Despite the operation’s success, authorities caution that variants of Lumma Stealer could resurface under different names. Historical patterns suggest that when major malware services are dismantled, their codebase often reappears in derivative tools distributed through darknet marketplaces. Investigators are now working to identify the developers behind LummaC2, though they suspect the involvement of a well-organized cybercrime group based in Eastern Europe.

Preventive Measures

To protect against Lumma Stealer and similar threats, cybersecurity experts recommend:

Regular Software Updates: Ensure all applications, especially web browsers, are up to date to mitigate vulnerabilities.

Caution with Downloads: Avoid downloading software from unverified sources, as they may contain malicious payloads.

Awareness of Phishing Attempts: Be vigilant against deceptive emails and websites that attempt to trick users into executing malicious scripts.

Utilize Security Solutions: Employ comprehensive security software that can detect and block threats like Lumma Stealer.

The legal actions taken by Microsoft and its partners underscore the growing threat posed by information-stealing malware. While the takedown of Lumma Stealer marks a significant victory, experts caution that the malware's success may inspire the development of similar threats. Continued vigilance and collaboration among tech companies, law enforcement, and users are essential to combat the evolving landscape of cybercrime.


Ad Banner
Advertisement by Open Privilege
Tech Singapore
Image Credits: Unsplash
TechMay 22, 2025 at 9:30:00 AM

SingTel posts higher profit announces share buyback and expanded asset recycling

[SINGAPORE] Singapore Telecommunications (SingTel) on Thursday reported a 9% increase in full-year profit, supported by robust results from its Australian arm Optus and...

Tech Europe
Image Credits: Unsplash
TechMay 21, 2025 at 1:00:00 PM

EU spectrum battle escalates

[EUROPE] A significant dispute has emerged within the European Union regarding the allocation of the upper 6GHz frequency band, a pivotal spectrum range...

Tech World
Image Credits: Unsplash
TechMay 21, 2025 at 12:30:00 PM

Google introduced AI-powered search

[WORLD] In an effort to enhance user experience and streamline information discovery, Google has unveiled an AI-powered mode for its search engine. This...

Tech Malaysia
Image Credits: Unsplash
TechMay 21, 2025 at 12:30:00 AM

Malaysia's AI dilemma in the US-China tech rivalry

[MALAYSIA] Malaysia announced plans to build a pioneering artificial intelligence system powered by chips from Huawei Technologies Co.—only to backtrack the following day,...

Tech World
Image Credits: Unsplash
TechMay 20, 2025 at 6:00:00 AM

Microsoft teams with xAI as Grok chatbot controversy sparks transparency push

[WORLD] Microsoft announced Monday that its Azure cloud platform will now support technology from xAI, the artificial intelligence startup founded by Elon Musk....

Tech World
Image Credits: Unsplash
TechMay 20, 2025 at 12:30:00 AM

Russia fines Apple over alleged LGBT propaganda violations

[WORLD] A Russian court has imposed a fine of 7.5 million roubles ($93,500) on U.S. tech giant Apple for three separate violations of...

Tech United States
Image Credits: Unsplash
TechMay 19, 2025 at 6:00:00 PM

Tech giants flatten management to speed up decision-making

[UNITED STATES] In a widespread effort to streamline operations, companies are increasingly cutting layers of middle management — a strategy known as "flattening...

Tech Europe
Image Credits: Unsplash
TechMay 19, 2025 at 10:30:00 AM

Telegram defends free speech in Romania

[EUROPE] Pavel Durov, founder of the Telegram messaging platform, announced Sunday that he had refused a request from an unnamed Western European government...

Tech World
Image Credits: Unsplash
TechMay 19, 2025 at 9:30:00 AM

Samsung SDI lowers share price amid market turmoil

[WORLD] Samsung SDI has reduced the price of its upcoming rights offering by 17%, setting the new share price at 140,000 won ($100.37),...

Tech United States
Image Credits: Unsplash
TechMay 16, 2025 at 11:30:00 AM

US lawmakers push for chip Security Act to combat smuggling

[WORLD] A bipartisan coalition of eight U.S. lawmakers introduced a bill on Thursday requiring manufacturers of artificial intelligence (AI) chips, such as Nvidia,...

Tech United States
Image Credits: Unsplash
TechMay 16, 2025 at 8:30:00 AM

Meta pushes to dismiss antitrust lawsuit

[UNITED STATES] Meta Platforms Inc. has filed a motion requesting a U.S. federal judge to dismiss the Federal Trade Commission's (FTC) antitrust lawsuit,...

Ad Banner
Advertisement by Open Privilege
Load More
Ad Banner
Advertisement by Open Privilege