LummaC2: 394,000 Windows Computers Worldwide Infected by Dangerous Malware

May 23, 2025  15:13

Microsoft has announced the widespread proliferation of the LummaC2 malware, which infected over 394,000 Windows computers globally, including in Russia, between March 16 and May 16, 2025. Developed by the cybercriminal group Storm-2477, this infostealer poses a serious threat by stealing sensitive user data.

How Does LummaC2 Work?

LummaC2 operates as a Malware-as-a-Service (MaaS), making it accessible to numerous cybercriminals. Its primary goal is to collect personal information, including:

Credentials and cookies from browsers (Chrome, Edge, Firefox). Data from cryptocurrency wallets (MetaMask, Electrum, Exodus). Information from VPN clients, email programs, FTP applications, and Telegram. Files in PDF, DOCX, and RTF formats. System telemetry: data about the processor, OS version, and installed applications.

Once infected, the malware transmits collected data to attackers’ servers, where it is used for financial fraud, blackmail, or further attacks, including ransomware deployment.

How Does LummaC2 Spread?

LummaC2 infiltrates devices through various channels:

Phishing emails disguised as legitimate messages, such as those impersonating Booking.com. Malvertising (malicious ads) on fake or compromised websites. Hidden downloads via fake updates for popular software like Chrome or Notepad++. Trojans and deceptive CAPTCHAs that trick users into executing malicious code.

Particularly dangerous are fake installation files masquerading as updates for well-known software, which users download from untrustworthy sources.

Consequences of Infection

LummaC2 causes significant harm to both individuals and organizations. In 2025, it was used to target:

Gaming communities and educational systems. Critical industries: manufacturing, logistics, healthcare, finance, and telecommunications.

Stolen credentials led to major data breaches at companies like PowerSchool and Snowflake, as well as network routing disruptions, such as the Orange Spain incident.

How to Protect Yourself?

Microsoft and cybersecurity experts recommend the following measures to guard against LummaC2:

Download software only from official websites. Avoid files from suspicious sources, especially fake updates. Use multi-factor authentication (MFA) to secure accounts. Keep antivirus software updated. Microsoft confirmed that Windows Defender, Defender for Office 365, and Defender for Endpoint now detect LummaC2. Be cautious with emails and links. Avoid opening attachments or clicking links from unverified sources. Scan suspicious downloads. Use antivirus software to check files before installation.

Microsoft and Authorities’ Response

Microsoft, in collaboration with law enforcement from the US, Europe, and Japan, conducted an operation to dismantle LummaC2’s infrastructure. With a US court order, approximately 2,300 domains forming the backbone of the stealer’s network were seized. The US Department of Justice took control of the central command structure, while Europol and Japan’s cybercrime control center blocked local infrastructure. Over 1,300 domains were redirected to Microsoft’s “sinkholes” for traffic analysis.

Despite this success, cybercriminals, including Lumma’s primary developer, known as Shamel from Russia, are attempting to rebuild the infrastructure. Microsoft continues to monitor and block new domains.

In Summary…

LummaC2 is one of the most dangerous cyber threats of 2025, impacting hundreds of thousands of computers and endangering personal and corporate data. Thanks to Microsoft and its international partners, its infrastructure has been significantly disrupted, but users must remain vigilant. Regular updates to security systems, caution with downloads, and reliance on trusted sources can minimize the risk of infection.

Follow NEWS.am Tech on Facebook and Twitter