LummaStealer Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
14
occurrences
First Seen
November 3, 2025
Last Seen
August 19, 2026

Related Threat Clusters

  • Global Anti-Fraud Operation Nets 5,811 Arrests and $293 Million Seized

    Operation First Light 2026, coordinated by INTERPOL, led to the arrest of 5,811 suspects and the interception of $293 million in illicit assets across 97 countries. This operation, which ran from January 15 to April 30,…

    34 articles · Updated July 9, 2026
  • Attackers Exploit AI Brand Trust to Distribute Malware

    Sophos X-Ops reported that attackers are impersonating popular AI brands like Claude, ChatGPT, and Copilot to distribute malware, including information stealers and backdoors. Over a year, they reviewed 86 Managed…

    2 articles · Updated August 21, 2026
  • MSHTA Utility Exploited in Ongoing Malware Campaigns

    Bitdefender researchers have identified that the Microsoft HTML Application Host (MSHTA) utility is being actively exploited by cybercriminals to deliver a variety of malware, including infostealers and loaders. Despite…

    8 articles · Updated May 19, 2026
  • Hackers Collaborate with Organized Crime to Steal Cargo Shipments

    Cybercriminals are infiltrating trucking and freight companies to steal cargo shipments before they reach stores. Research from Proofpoint indicates that these hackers are using remote monitoring and management tools to…

    11 articles · Updated November 4, 2025
  • LummaStealer Infections Rise Following CastleLoader Campaigns

    LummaStealer infections have surged due to social engineering campaigns utilizing the ClickFix technique to distribute CastleLoader malware. This infostealer, operating as a malware-as-a-service platform, had previously…

    7 articles · Updated February 11, 2026
  • ClickFix Attack Wave Targets Windows Users with StealC Malware

    A new social engineering campaign named ClickFix is targeting Windows users by presenting fake CAPTCHA verification pages. Victims are led to compromised websites that display fraudulent Cloudflare security checks,…

    221 articles · Updated February 13, 2026
  • Hackers Collaborate with Organized Crime to Steal Cargo Shipments

    Cybercriminals are partnering with organized crime groups to hijack cargo shipments from trucking and freight companies. Utilizing remote monitoring and management tools, these hackers are able to infiltrate logistics…

    18 articles · Updated December 1, 2025

Recent Intelligence Reports

  • Fake AI, real malware: Attackers impersonating AI brands — News.Sophos · August 19, 2026
  • Dramatic cybercrime increase in Asia,South Pacific, says Interpol — Rnz.Co.Nz · June 21, 2026
  • Hackers Abuse MSHTA Legacy Windows Tool to Deliver LummaStealer and Amatera Malware — Cybersecuritynews · May 20, 2026
  • Hackers Exploit MSHTA to Deploy LummaStealer and Amatera Malware — Gbhackers · May 20, 2026
  • Attackers turn ancient Windows utility MSHTA into Swiss Army knife of hacking — Cybernews · May 19, 2026
  • Microsoft's MSHTA Legacy Tool Still Powers Malware Campaigns on Windows — Bitdefender · May 19, 2026
  • Internet Explorer may be dead, but its ghost still runs malware — Csoonline · May 19, 2026
  • Fake CAPTCHA Attacks Fuel LummaStealer Malware Surge — Cyberpress · February 12, 2026

CVSS v3.1 Breakdown