Validin will be at Black Hat 2026, Booth #6200 — schedule time to meet with us for an enterprise demo or an online meeting

Lumma Stealer

Aliases: LummaC2 Stealer • Lumma Stealer is a C2/malware loader that delivers various malicious payloads, including information stealers and cryptocurrency stealers.
Profile
Malware
Category
Loader
Threat Type
Unknown
Country
lumma_stealer
Profile Key
The profile key is a unique identifier for this threat actor. It can be used to query the Validin APIs as the threat_key for information about this threat actor.
Last Updated
Summary
Indicator Activity
Loading activity...
No indicators recorded yet.
Description

Lumma Stealer is a malware loader that delivers a variety of malicious payloads, including information stealers, backdoors, and cryptocurrency stealers. It is often used in targeted attacks against organizations in the United States and Europe. LegionLoader employs various anti-analysis and evasion techniques, such as VM/sandbox detection and string obfuscation. It also features a built-in cryptocurrency stealer and browser credential harvester.

Aliases (1)
LummaC2 Stealer
Alias
Targets (2)
Windows
Target
United States
Target
External Sources