Lumma Malware Targets Windows for Data Theft

21 Oct 2025

A resurgence in the deployment of Lumma, a sophisticated malware, is targeting Windows systems globally. This infostealer, available as Malware-as-a-Service, enables low-skilled attackers to access high-value credentials and sensitive data with minimal effort.

Distribution and Execution

Lumma is commonly distributed as disguised cracked or pirated software, utilizing platforms like MEGA for its spread. Once downloaded, the malware is installed through a Nullsoft Scriptable Install System (NSIS) installer, deploying its payload into the %Temp% directory and activating a decoy document that triggers the malicious process. An AutoIt-based loader then completes the deployment by executing the malware's encrypted core.

Techniques and Evasion

Utilizing advanced shellcode injection and process hollowing techniques, the Lumma payload embeds itself into benign processes, greatly reducing detection rates. It establishes communication with command-and-control domains, such as diadtuky[.]su, to exfiltrate collected data. This data includes browser credentials, session cookies, and cryptocurrency wallet information.

Lumma employs evasive tactics by monitoring running processes, disabling its functions when security solutions like Sophos, Norton, or Bitdefender are detected. Its modular architecture allows for frequent updates enhancing its ability to evade traditional signature-based detection methods.

Detection and Mitigation Strategies

Effective detection of Lumma requires behavior-based Endpoint Detection and Response (EDR) systems. Such systems should track command chains, file alterations, and process anomalies. Security measures should include avoiding the storage of sensitive credentials in browsers, enforcing multi-factor authentication, and monitoring for unusual process executions initiated by installer files.

  • MD5 IOCs: E6252824BE8FF46E9A56993EEECE0DE6E1726693C85E59F14548658A0D82C7E8.
  • Domains involved: rhussois[.]su, todoexy[.]su.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6313786
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1241826
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
488993
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
452496
downloads

News and reviews for Desktop Windows

Epic Games Store Offers Free PC Horror Games This Week

Epic Games Store releases free horror games, Bendy and Five Nights at Freddy's, boosting interest in horror games.

Read more

Microsoft Expands Xbox FSE to MSI Claw Handhelds

Microsoft adds Xbox FSE to MSI Claw. Available via Windows 11 Insider Preview Build. More OEMs, including Lenovo's Legion Go 2, to follow.

Read more

Brotato Abyssal Terrors DLC Free on Steam Until 2025-11-07

Brotato players can secure a free Abyssal Terrors DLC on Steam by 2025-11-07, offering seaworthy content from Blobfish.

Read more

Condemned Delisted from Major Gaming Platforms

Condemned delisted from Steam and Xbox store, no longer on GOG. Fans speculate remaster.

Read more

Demon King Game Update and Sale on Steam

Labyrinth of the Demon King updated on Steam with new content and a 25% sale.

Read more

Europa Universalis 5 Debuts with Complex Gameplay in EU5

Europa Universalis 5 launches in EU5, offering intricate grand strategy with new features and enhanced systems. Expect deep simulation and engaging history.

Read more

Europa Universalis 5 Adds Complexity to Historical Strategy

EU5, released by Paradox Interactive, challenges players with complex simulation of history from 1337 to 1836.

Read more

GOG Offers Free Stasis for Limited Time

GOG celebrates Halloween with a 48-hour Stasis giveaway until 2025-10-31. Claim to keep permanently.

Read more

GOG Offers Stasis Game for Free Until November 3

GOG gives away Stasis, a horror adventure game by The Brotherhood, free till 2025-11-03. Boosts interest in upcoming games, accessible for casual players.

Read more

Aspyr Releases Controversial Deus Ex Remastered

Deus Ex Remastered, launched by Aspyr on 2026-02-05, sparks criticism over visual updates, affecting long-term fans.

Read more