Lumma Malware Targets Windows for Data Theft

21 Oct 2025

A resurgence in the deployment of Lumma, a sophisticated malware, is targeting Windows systems globally. This infostealer, available as Malware-as-a-Service, enables low-skilled attackers to access high-value credentials and sensitive data with minimal effort.

Distribution and Execution

Lumma is commonly distributed as disguised cracked or pirated software, utilizing platforms like MEGA for its spread. Once downloaded, the malware is installed through a Nullsoft Scriptable Install System (NSIS) installer, deploying its payload into the %Temp% directory and activating a decoy document that triggers the malicious process. An AutoIt-based loader then completes the deployment by executing the malware's encrypted core.

Techniques and Evasion

Utilizing advanced shellcode injection and process hollowing techniques, the Lumma payload embeds itself into benign processes, greatly reducing detection rates. It establishes communication with command-and-control domains, such as diadtuky[.]su, to exfiltrate collected data. This data includes browser credentials, session cookies, and cryptocurrency wallet information.

Lumma employs evasive tactics by monitoring running processes, disabling its functions when security solutions like Sophos, Norton, or Bitdefender are detected. Its modular architecture allows for frequent updates enhancing its ability to evade traditional signature-based detection methods.

Detection and Mitigation Strategies

Effective detection of Lumma requires behavior-based Endpoint Detection and Response (EDR) systems. Such systems should track command chains, file alterations, and process anomalies. Security measures should include avoiding the storage of sensitive credentials in browsers, enforcing multi-factor authentication, and monitoring for unusual process executions initiated by installer files.

  • MD5 IOCs: E6252824BE8FF46E9A56993EEECE0DE6E1726693C85E59F14548658A0D82C7E8.
  • Domains involved: rhussois[.]su, todoexy[.]su.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6180845
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1183856
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
453262
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
449465
downloads

News and reviews for Desktop Windows

Frogwares Delays Sinking City 2 to 2026

Frogwares shifts Sinking City 2 release to 2026 amid Ukraine war challenges.

Read more

Microsoft Fixes WinRE Glitch in Windows 11 Patch

Microsoft's WinRE patch KB5070773 for Windows 11 users, fixing USB input issues caused by the October update.

Read more

Lumma Malware Targets Windows for Data Theft

Lumma, a sophisticated malware, resurfaces targeting Windows systems for credential theft via Malware-as-a-Service. Impacting global cybersecurity.

Read more

Jackbox Party Pack 11 Launches With Five New Games

Jackbox launches Party Pack 11 on 2023-10-23 with five original games. Includes fantasy trivia and social deduction options.

Read more

Guide Reveals Top Outfits in Bloodlines 2

Discover how clan powers unlock outfits in Bloodlines 2 and influence NPC interactions.

Read more

Over 500 Games at Steam Next Fest Use Generative AI

504 Steam Next Fest demos disclosed using Generative AI for development, impacting game creation roles.

Read more

SWTOR Update 7.8 Enhances Outer Rim Gameplay

SWTOR update 7.8 brings dynamic encounters to Dantooine, adding new challenges and player rewards.

Read more

Reveals Bloodlines 2 Main Mission List

Bloodlines 2 unveils its main missions, featuring 21 quests in a mysterious RPG setting. Side quests to follow.

Read more

Salt Typhoon Targets European Telecom via Citrix Exploit

Salt Typhoon cyber group attacked a European telecom in July 2025, exploiting Citrix devices.

Read more

N++ Update Adds Challenging Levels for 10th Anniversary

Metanet celebrates N++'s 10th anniversary with the free Ten++ update, adding new levels and features to the platformer game.

Read more