LummaC2 Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
26
occurrences
First Seen
November 24, 2025
Last Seen
July 14, 2026

LummaC2 is a malware family tracked across 13 threat clusters and 26 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity July 14, 2026.

Related Threat Clusters

  • EU Sanctions Russia Over Ongoing Cyber Espionage Campaign

    The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…

    165 articles · Updated July 13, 2026
  • EU Sanctions Vitaly Kovalev, Ransomware Leader of Trickbot Group

    On July 14, 2026, the European Union, in coordination with the U.S. and U.K., sanctioned Vitaly Nikolayevich Kovalev, known as 'Stern,' a key figure in the Trickbot ransomware syndicate. Kovalev is linked to over $300…

    4 articles · Updated July 15, 2026
  • Chronus Group Breach Exposes 36 Million Mexican Citizens' Data

    In January 2026, the Chronus Group executed a significant data breach against the Mexican government, compromising 2.3 terabytes of sensitive data from at least 25 agencies. The breach exposed personal information of up…

    2 articles · Updated May 28, 2026
  • The Gentlemen Ransomware Group Exploits Fortinet Flaws and AI Tools

    The Gentlemen ransomware group has emerged as a significant threat in 2026, exploiting vulnerabilities in Fortinet systems, particularly CVE-2024-55591, an authentication bypass flaw. They have been observed using…

    4 articles · Updated June 3, 2026
  • Global Anti-Fraud Operation Nets 5,811 Arrests and $293 Million Seized

    Operation First Light 2026, coordinated by INTERPOL, led to the arrest of 5,811 suspects and the interception of $293 million in illicit assets across 97 countries. This operation, which ran from January 15 to April 30,…

    34 articles · Updated July 9, 2026
  • Google Chrome Implements Device Bound Session Credentials to Combat Cookie Theft

    Google has launched Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, aimed at preventing session cookie theft by infostealer malware. This security feature, which will extend to macOS in a future…

    9 articles · Updated April 9, 2026
  • Enterprises Struggle with Stolen Credential Threats in 2026

    In 2026, stolen credentials are identified as a critical cybersecurity risk, with 85% of organizations ranking them as a high priority. Despite this, many enterprises rely on inadequate checkbox solutions and generic…

    2 articles · Updated April 6, 2026
  • World Password Day 2026: AI and Infostealers Redefine Cybersecurity Threats

    On World Password Day 2026, experts highlight that traditional password security measures are inadequate against modern threats. Infostealer malware, such as LummaC2 and RedLine, now operates in a…

    2 articles · Updated May 7, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1551 articles · Updated February 12, 2026
  • Revival of Finger Command in ClickFix Malware Attacks

    Threat actors are exploiting the decades-old 'finger' command in new ClickFix malware attacks to execute remote commands on Windows devices. The command, which was historically used to retrieve user information on Unix…

    4 articles · Updated November 17, 2025

Recent Intelligence Reports

  • “Stern” Ransomware Operator Sanctioned by EU — Chainalysis · July 14, 2026
  • EU imposes sanctions on 9 Russians and 4 companies over cyberattacks — Pravda.Ua · July 14, 2026
  • EU sanctions nine Russians, four entities over cyber — Newpostafrica · July 14, 2026
  • Russian cyber-attacks and destabilising activities: Council sanctions nine individuals and four entities — Consilium.Europa.Eu · July 13, 2026
  • Russian cyber-attacks and destabilising activities: Council sanctions nine individuals and four entities — Consilium.Europa.Eu · July 13, 2026
  • Russian cyber-attacks and destabilising activities: Council sanctions nine individuals and four entities — Consilium.Europa.Eu · July 13, 2026
  • Dramatic Cybercrime Increase In Asia, South Pacific, Says Interpol — Pacific.Scoop.Co.Nz · June 22, 2026
  • Dramatic cybercrime increase in Asia,South Pacific, says Interpol — Rnz.Co.Nz · June 21, 2026

CVSS v3.1 Breakdown