HeadlinesBriefing favicon HeadlinesBriefing.com

Lumma Stealer Malware Returns With Hard-to-Detect Attacks

Ars Technica - All content •
×

The Lumma Stealer malware, which infected nearly 395,000 Windows computers before being disrupted last year, has made a significant comeback. Security researchers report the malware is now operating "back at scale" with sophisticated attacks that are difficult to detect.

Last May, law enforcement seized 2,300 domains and infrastructure used by Lumma, which had become the "go-to tool" for multiple crime groups including Scattered Spider. The malware-as-a-service model, which sold for up to $2,500 for premium versions, had been effectively crippled. However, the recent resurgence demonstrates how quickly criminal operations can rebuild.

The new campaigns heavily rely on "ClickFix" social engineering lures, particularly fake CAPTCHAs that trick users into copying malicious commands into their Windows terminal. The malware now uses CastleLoader, which runs entirely in memory and employs heavy obfuscation to evade detection. Bitdefender researchers warn that once installed, Lumma can steal browser credentials, cookies, and personal documents, giving attackers complete control over infected machines.