Participating company report

# Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool

Microsoft On the Issues, May 21, 2025. Court order, approximately 2,300 domains seized, more than 394,000 infected computers identified between 2025-03-16 and 2025-05-16, partner roles.

**Source type:** Participating company report

**Published:** May 21, 2025

**Research grade:** T1

**Used in entries:** 8

## Bibliographic record

**Publisher:** Microsoft On the Issues

**Published:** May 21, 2025

**Source type:** Participating company report

**Research grade:** Source grade T1

**Language:** English

**Official record:** Not an official publication

**Address:** [https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/](https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/)

**What it supports:** Court order, approximately 2,300 domains seized, more than 394,000 infected computers identified between 2025-03-16 and 2025-05-16, partner roles

**Dataset id:** src\_microsoft\_lumma\_2025

## Research notes

- URL verified as present in the research record.
- Microsoft is a directly participating party, so this is graded T1, but a DOJ release remains the preferred P1 primary source.

How this source is used

Cited 8 times across 4 record types.

The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.

Sources were reviewed to a research cutoff of August 20, 2026. Addresses recorded after that date are not reflected here.

## Cited by

### Takedown records

1 citation

Cited on the takedown record itself.

-
[Lumma Stealer disruption](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Malware and botnets, May 2025

Primary source

### Organization roles

4 citations

Cited for an organization's recorded role in a takedown.

-
[Microsoft Digital Crimes Unit](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Co-lead, Lumma Stealer disruption

Primary source
-
[United States Department of Justice](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Co-lead, Lumma Stealer disruption

Primary source
-
[Japan Cybercrime Control Center](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Supporting, Lumma Stealer disruption

Primary source
-
[Cloudflare](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Technical partner, Lumma Stealer disruption

Primary source

### Infrastructure

2 citations

Cited for infrastructure recorded as acted on.

-
[approximately 2,300 domains](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Domains seized, Lumma Stealer disruption

Primary source
-
[more than 394,000 malware installations](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Malware installations sinkholed, Lumma Stealer disruption

Primary source

### Later activity

1 citation

Cited for activity recorded after the takedown.

-
[Lumma Stealer rebound](https://takedownindex.org/takedowns/lumma-stealer-disruption)

Same service on replacement infrastructure, Lumma Stealer disruption

Primary source

[All sources](https://takedownindex.org/sources)
