Lumma Stealer
malware for Microsoft Windows

Lumma Stealer is an infostealer malware as a service program developed for Microsoft Windows.
Technical overview
Lumma Stealer is distributed by affiliates via a number of campaigns including phishing emails, malicious advertisements posing as legitimate downloads, and compromised websites. It is frequently associated with fake CAPTCHA pages, which prompt the user to paste a command into the run box. It steals data from a number of programs including web browsers, crypto wallets and chat applications, as well as user files. The exfiltrated data is sent to a number of hardcoded control servers, falling back to Telegram, Dropbox and Steam if the servers are unreachable.
Lumma Stealer employs advanced obfuscation techniques, and uses process hollowing to impersonate legitimate programs for the purposes of evading detection. It delays detonation until a sufficient amount of human-like activity has occurred. Instead of using WinAPI, it performs direct syscalls.
History
Lumma is believed to have first originated on cybercrime forums in 2022.
From March to May 2025, Microsoft identified 394,000 computers that were infected with Lumma.
This brief starts where responsible research should: with the source description of “Lumma Stealer” as malware for Microsoft Windows. Everything that follows is an evidence route, not borrowed authority.
Why this record matters
The subject matters to the general reference register because the source frames it as malware for Microsoft Windows. Its deeper value depends on whether names, dates, institutions and citations support that framing.
Named sources, stable identifiers and responsible institutions provide the strongest route from overview to verifiable evidence. The source revision retrieved here is dated May 15, 2026. The linked authority identifier is Q135483074. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2022 and 2025.
A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “Lumma Stealer”, its source revision and the description used here.
- Expand the search: follow Lumma Stealer primary sources, Lumma Stealer archive and Lumma research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Lumma Stealer”?
- Which cited source is closest to the event, object or claim?
- What terminology or title could unlock a more precise catalogue search?
Search terms from this dossier
This entry incorporates text from “Lumma Stealer” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.