Skip to main content
Back to the takedown index

Lumma Stealer disruption

May 2025, Malware and botnets
Led by Microsoft Digital Crimes Unit, United States Department of Justice

Verified core entry, last reviewed August 21, 2026

What was taken down?

Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.[1][2][3]

See what happened

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Partial

See people and accountability

Did it stay down?

After this action the service returned under the same operators, first seen May 2025. The replacement was itself seized in a later action. High confidence in the link between the two.

See what happened afterward

Hybrid civil and criminal action in which Microsoft's Digital Crimes Unit obtained a US court order to seize Lumma command domains while DOJ seized the central command structure and Europol and Japanese partners suspended locally based infrastructure.[1][2][3]

Announced May 21, 2025.

Date
May 13 to May 21, 2025
Target
Lumma Stealer, malware as a service infostealer
Activity
Malware and botnets, Fraud and stolen data
Operational lead
Microsoft DCU and DOJ
Partners
EC3, Cloudflare, and 1 more[2][3]
Jurisdiction
United States, Japan, and European Union
Outcome
Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.
Status
Completed
Legal mechanism
US civil court order (Northern District of Georgia) plus DOJ criminal seizure process; Europol EC3 and Japan JC3 coordination
Group accounted for
Partial

Infrastructure

2,300 domains seized and 394,000 malware installations sinkholed. Command and control servers seized, with no count in the record.

approximately 2,300
domains seized
more than 394,000
malware installations sinkholed
Identifier Recorded as Status Notes
Not published approximately 2,300 domains Seized, United States Approximately 2,300 domains forming the backbone of Lumma's infrastructure were seized or redirected to Microsoft sinkholes under a civil court order.[3]
Not published Command and control server Seized, United States DOJ seized the central command structure and the marketplaces where the malware was sold.[1]
Not published more than 394,000 malware installations Sinkholed More than 394,000 infected Windows computers identified globally between 2025-03-16 and 2025-05-16.[3]

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

No arrests or charges accompanied the action, the developer was not apprehended, and the service resumed operating within days.

Principal developer known publicly only by the alias Shamel and believed to be in Russia.

See the organizations and roles behind this action

Operation rebounded within days on new infrastructure; developer remains at large.[1][2][3]

  1. May 2025

    Lumma Stealer rebound. Same service on replacement infrastructure. Confidence: Medium. No later seizure recorded.[3]

    Indicators associated with the operation reappeared within days of the seizure and the developer publicly acknowledged the disruption while continuing to operate.

  2. May 2025

    Lumma replacement domains (3 domains, seized same wave). Same operators. Confidence: High. Seized in a later action.[4]

    Operators registered three replacement domains within approximately one day of the initial seizure; DOJ/Microsoft seized those as well within the same action window.

May 2025

Lumma Stealer rebound. Same service on replacement infrastructure. Confidence: Medium. No later seizure recorded.[3]

Indicators associated with the operation reappeared within days of the seizure and the developer publicly acknowledged the disruption while continuing to operate.

May 2025

Lumma replacement domains (3 domains, seized same wave). Same operators. Confidence: High. Seized in a later action.[4]

Operators registered three replacement domains within approximately one day of the initial seizure; DOJ/Microsoft seized those as well within the same action window.

Return class B. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. How this index handles it.

Numbered markers throughout this entry link to the source that supports the claim beside them.

Official sources

  1. [1]
    US Department of Justice statement on the seizure of Lumma Stealer command infrastructure

    United States Department of Justice, May 21, 2025, Source grade P1

    Seizure of the central command structure and the marketplaces selling the malware

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

  2. [2]
    Europol statement on the Lumma Stealer disruption

    Europol, May 21, 2025, Source grade P2

    Suspension of Europe-based infrastructure

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Additional reporting and technical analysis

  1. [3]
    Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool

    Microsoft On the Issues, May 21, 2025, Source grade T1

    Court order, approximately 2,300 domains seized, more than 394,000 infected computers identified between 2025-03-16 and 2025-05-16, partner roles

    Open source
  2. [4]
    Lumma Stealer operators register replacement domains within a day of seizure

    Aggregated security reporting, May 22, 2025, Source grade S1

    Establishes that Lumma operators stood up three replacement domains within roughly a day of the initial May 2025 seizure, which DOJ/Microsoft subsequently also seized.

    No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note.
  • Microsoft reported identifying more than 394,000 infected Windows computers globally between 2025-03-16 and 2025-05-16.
  • PROBABLE EDGE CASE on the private-action exclusion. Included because DOJ seized infrastructure under criminal process alongside the civil order; a purely civil Microsoft action would have been excluded.