Lumma Stealer disruption
Verified core entry, last reviewed August 21, 2026
What was taken down?
Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.[1][2][3]
See what happenedWhat happened to the people?
No individual outcomes are recorded against this entry.
Group accounted for: Partial
Did it stay down?
After this action the service returned under the same operators, first seen May 2025. The replacement was itself seized in a later action. High confidence in the link between the two.
See what happened afterwardHybrid civil and criminal action in which Microsoft's Digital Crimes Unit obtained a US court order to seize Lumma command domains while DOJ seized the central command structure and Europol and Japanese partners suspended locally based infrastructure.[1][2][3]
Announced May 21, 2025.
- Date
- May 13 to May 21, 2025
- Target
- Lumma Stealer, malware as a service infostealer
- Activity
- Malware and botnets, Fraud and stolen data
- Operational lead
- Microsoft DCU and DOJ
- Partners
- EC3, Cloudflare, and 1 more[2][3]
- European Cybercrime Centre , coordinator
- Cloudflare , technical partner
- Japan Cybercrime Control Center , supporting
- Jurisdiction
- United States, Japan, and European Union
- Outcome
- Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.
- Status
- Completed
- Legal mechanism
- US civil court order (Northern District of Georgia) plus DOJ criminal seizure process; Europol EC3 and Japan JC3 coordination
- Group accounted for
- Partial
Infrastructure
2,300 domains seized and 394,000 malware installations sinkholed. Command and control servers seized, with no count in the record.
- approximately 2,300
- domains seized
- more than 394,000
- malware installations sinkholed
| Identifier | Recorded as | Status | Notes |
|---|---|---|---|
| Not published | approximately 2,300 domains | Seized, United States | Approximately 2,300 domains forming the backbone of Lumma's infrastructure were seized or redirected to Microsoft sinkholes under a civil court order.[3] |
| Not published | Command and control server | Seized, United States | DOJ seized the central command structure and the marketplaces where the malware was sold.[1] |
| Not published | more than 394,000 malware installations | Sinkholed | More than 394,000 infected Windows computers identified globally between 2025-03-16 and 2025-05-16.[3] |
Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.
No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.
Group accounted for: Partial
No arrests or charges accompanied the action, the developer was not apprehended, and the service resumed operating within days.
Principal developer known publicly only by the alias Shamel and believed to be in Russia.
Operation rebounded within days on new infrastructure; developer remains at large.[1][2][3]
-
May 2025
Lumma Stealer rebound. Same service on replacement infrastructure. Confidence: Medium. No later seizure recorded.[3]
Indicators associated with the operation reappeared within days of the seizure and the developer publicly acknowledged the disruption while continuing to operate.
-
May 2025
Lumma replacement domains (3 domains, seized same wave). Same operators. Confidence: High. Seized in a later action.[4]
Operators registered three replacement domains within approximately one day of the initial seizure; DOJ/Microsoft seized those as well within the same action window.
May 2025
Lumma Stealer rebound. Same service on replacement infrastructure. Confidence: Medium. No later seizure recorded.[3]
Indicators associated with the operation reappeared within days of the seizure and the developer publicly acknowledged the disruption while continuing to operate.
May 2025
Lumma replacement domains (3 domains, seized same wave). Same operators. Confidence: High. Seized in a later action.[4]
Operators registered three replacement domains within approximately one day of the initial seizure; DOJ/Microsoft seized those as well within the same action window.
Return class B. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. How this index handles it.
Numbered markers throughout this entry link to the source that supports the claim beside them.
Official sources
-
[1]
US Department of Justice statement on the seizure of Lumma Stealer command infrastructure
Seizure of the central command structure and the marketplaces selling the malware
-
[2]
Europol statement on the Lumma Stealer disruption
Suspension of Europe-based infrastructure
Additional reporting and technical analysis
-
[3]
Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime toolOpen source
Court order, approximately 2,300 domains seized, more than 394,000 infected computers identified between 2025-03-16 and 2025-05-16, partner roles
-
[4]
Lumma Stealer operators register replacement domains within a day of seizure
Establishes that Lumma operators stood up three replacement domains within roughly a day of the initial May 2025 seizure, which DOJ/Microsoft subsequently also seized.
- Microsoft reported identifying more than 394,000 infected Windows computers globally between 2025-03-16 and 2025-05-16.
- PROBABLE EDGE CASE on the private-action exclusion. Included because DOJ seized infrastructure under criminal process alongside the civil order; a purely civil Microsoft action would have been excluded.