Bitdefender
LummaStealer Infections Rise Following CastleLoader Campaigns
First seen 12 Feb 2026, 00:29 UTC
•



+2
•41.3
Export
Article Content
Browse articles
LummaStealer infections have surged due to social engineering campaigns utilizing the ClickFix technique to distribute CastleLoader malware. This infostealer, operating as a malware-as-a-service platform, had previously been disrupted in May 2025 when law enforcement seized 2,300 domains associated with it.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2025-05-01
Law enforcement seized 2,300 domains linked to LummaStealer
2026-02-11
Surge in LummaStealer infections reported
More articles in this cluster
Continue Reading
Malicious Background Removal Tool Distributes RATs and Infostealers
Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop App
MSHTA Utility Exploited in Ongoing Malware Campaigns
CastleLoader Campaign Uses NeedleStealer to Target Crypto Users
Iran's Cyber Response to U.S. Military Strikes Expected Amid Rising Tensions
CastleLoader Malware Targets U.S. Government Entities