Malware, Threat Intelligence

Doxing campaign crashes Lumma infostealer activity

A person's hand holds a magnifying glass over an alert symbol on a cybersecurity interface. The image suggests security issues and vigilance.

Activity of the Lumma information-stealing malware, also known as LummaC2, has sharply declined amid an underground doxing campaign that exposed the five alleged primary members of the operation, which is also tracked as Storm-2477 and Water Kurita, last month, according to SecurityWeek.

Purported Lumma Stealer operation members, including its administrator and developer, had their email addresses, bank account details, passport numbers, and online profile links exposed in the Lumma Rats website as part of the campaign, which is believed to have been conducted by an actor with insider access, a report from Trend Micro showed.

"It is important to note that the accuracy of the doxed information and the actual involvement of the named individuals have not been independently verified. The campaign may also be motivated by personal or competitive grudges, and attribution should be treated with caution," said Trend Micro.

While Lumma infostealer usage dwindled after its operators failed to communicate with customers folllowing the incident, threat actors have since transitioned to the StealC and Vidar infostealers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds