Large-Scale Lumma Infostealer Campaign Abuses GitHub for Malware

Alan V Gutnov
Alan V Gutnov

Director of Strategy

 
July 19, 2025
2 min read

The Rise of Lumma Info Stealer

Lumma Info Stealer

The Malware-as-a-Service (MaaS) model is providing cybercriminals with accessible and sophisticated tools for executing cyber attacks. One notable example is the Lumma info stealer, which has been operational since 2022, targeting sensitive data such as login credentials and banking information. This malware is distributed on dark web forums and has seen increased visibility with various command-and-control (C2) servers identified.

Lumma Info Stealer Background

Lumma, also known as LummaC2, is marketed to threat actors with tiered subscription models, making it affordable for even novice attackers. Priced from USD 250, it has gained traction in marketplaces alongside other info stealers like Vidar and Racoon. The malware primarily targets cryptocurrency wallets and two-factor authentication (2FA) extensions, indicating a focus on high-value targets.

Attack Vectors and Distribution Methods

Lumma has been distributed through various deceptive methods, including masquerading as popular software like VLC or ChatGPT. Attackers also exploit phishing emails, often impersonating legitimate companies such as Bandai Namco to lure victims into executing malicious payloads. The malware targets Windows operating systems and multiple browsers, including Chrome and Firefox, to exfiltrate sensitive information.

Malicious Email Example

Data Exfiltration Techniques

Once Lumma is successfully executed, it employs HTTP POST requests to transmit stolen data to its C2 servers. Darktrace observed various devices infected with Lumma communicating with known C2 infrastructure, revealing a pattern of data exfiltration activities. The malware is capable of accessing and stealing browser data, cookies, and sensitive information from applications like AnyDesk and KeePass.

Device Event Log

Evasion Techniques and Defense Recommendations

Lumma employs various evasion techniques to avoid detection by security systems, including using obfuscation and encryption to mask payloads and leveraging trusted binaries like mshta.exe and wscript.exe to execute malicious code. Organizations are urged to adopt advanced security measures, such as Gopher Security's AI-Powered Zero Trust Platform, to enhance their defenses against evolving threats like Lumma.

Future Outlook

As cyber threats become more sophisticated, organizations need to focus on proactive risk management strategies. Gopher Security provides services like Cloud Access Security Broker and AI Inspection Engine for Traffic Monitoring to help businesses detect and respond to such threats effectively.

Explore our services at Gopher Security to safeguard your organization against the rising tide of cyber threats.

Alan V Gutnov
Alan V Gutnov

Director of Strategy

 

MBA-credentialed cybersecurity expert specializing in Post-Quantum Cybersecurity solutions with proven capability to reduce attack surfaces by 90%.

Related News

New Defense Bulletin Highlights Urgent Need for Quantum Readiness Against Harvest Now Decrypt Later Threats
Harvest Now Decrypt Later threat

New Defense Bulletin Highlights Urgent Need for Quantum Readiness Against Harvest Now Decrypt Later Threats

Discover why the 'Harvest Now, Decrypt Later' threat demands immediate quantum-resistant encryption. Learn how to protect sensitive data from future quantum attacks.

By Alan V Gutnov June 17, 2026 3 min read
common.read_full_article
Critical LangGraph Vulnerability Chain Allows Unauthorized Server Control in AI Agent Frameworks
LangGraph vulnerabilities

Critical LangGraph Vulnerability Chain Allows Unauthorized Server Control in AI Agent Frameworks

Discover how a chain of vulnerabilities in LangGraph allows unauthorized server control. Learn the risks to self-hosted AI agents and how to secure your framework.

By Divyansh Ingle June 16, 2026 4 min read
common.read_full_article
New Defense Bulletin Highlights Urgent Need for Quantum Readiness Against Harvest Now Decrypt Later Threats
Harvest Now Decrypt Later threat mitigation

New Defense Bulletin Highlights Urgent Need for Quantum Readiness Against Harvest Now Decrypt Later Threats

Are your secrets safe? Learn why 'Harvest Now, Decrypt Later' attacks are a critical threat and how to implement quantum-resistant encryption today.

By Brandon Woo June 15, 2026 5 min read
common.read_full_article
Active Directory Certificate Services Now Supports Post-Quantum Cryptography for Windows Environments
Post-Quantum Cryptography AD CS

Active Directory Certificate Services Now Supports Post-Quantum Cryptography for Windows Environments

Microsoft adds Post-Quantum Cryptography (PQC) to AD CS. Learn how ML-DSA and hybrid key exchanges protect Windows environments against Harvest Now, Decrypt Later.

By Edward Zhou June 12, 2026 4 min read
common.read_full_article