[Back to the takedown index](https://takedownindex.org/takedowns)

# Lumma Stealer disruption

May 2025, Malware and botnets
Led by [Microsoft Digital Crimes Unit](https://takedownindex.org/organizations/microsoft-digital-crimes-unit), [United States Department of Justice](https://takedownindex.org/organizations/united-states-department-of-justice)

Verified core entry, last reviewed August 21, 2026

What was taken down?

Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

[See what happened](#what-happened)

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Partial

[See people and accountability](#people)

Did it stay down?

After this action the service returned under the same operators, first seen May 2025. The replacement was itself seized in a later action. High confidence in the link between the two.

[See what happened afterward](#afterward)

## What happened

Hybrid civil and criminal action in which Microsoft's Digital Crimes Unit obtained a US court order to seize Lumma command domains while DOJ seized the central command structure and Europol and Japanese partners suspended locally based infrastructure.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

Announced May 21, 2025.

**Date:** May 13 to May 21, 2025

**Target:** Lumma Stealer, malware as a service infostealer

**Activity:** Malware and botnets, Fraud and stolen data

**Operational lead:** Microsoft DCU and DOJ

**Partners**

EC3, Cloudflare, and 1 more[[2]](#source-2)[[3]](#source-3)

- [European Cybercrime Centre](https://takedownindex.org/organizations/european-cybercrime-centre), coordinator
- [Cloudflare](https://takedownindex.org/organizations/cloudflare), technical partner
- [Japan Cybercrime Control Center](https://takedownindex.org/organizations/japan-cybercrime-control-center), supporting

**Jurisdiction:** United States, Japan, and European Union

**Outcome:** Approximately 2,300 malicious domains seized or redirected to Microsoft sinkholes; DOJ seized the central command structure and marketplaces selling the malware; European and Japanese infrastructure suspended.

**Status:** Completed

**Legal mechanism:** US civil court order (Northern District of Georgia) plus DOJ criminal seizure process; Europol EC3 and Japan JC3 coordination

**Group accounted for:** Partial

### Infrastructure

2,300 domains seized and 394,000 malware installations sinkholed. Command and control servers seized, with no count in the record.

| Identifier | Recorded as | Status | Notes |
| --- | --- | --- | --- |
| Not published | approximately 2,300 domains | Seized, United States | Approximately 2,300 domains forming the backbone of Lumma's infrastructure were seized or redirected to Microsoft sinkholes under a civil court order.[[3]](#source-3) |
| Not published | Command and control server | Seized, United States | DOJ seized the central command structure and the marketplaces where the malware was sold.[[1]](#source-1) |
| Not published | more than 394,000 malware installations | Sinkholed | More than 394,000 infected Windows computers identified globally between 2025-03-16 and 2025-05-16.[[3]](#source-3) |

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

## People and accountability

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Partial

No arrests or charges accompanied the action, the developer was not apprehended, and the service resumed operating within days.

Principal developer known publicly only by the alias Shamel and believed to be in Russia.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/lumma-stealer-disruption/organizations)

## What happened afterward

Operation rebounded within days on new infrastructure; developer remains at large.[[1]](#source-1)[[2]](#source-2)[[3]](#source-3)

May 2025

Lumma Stealer rebound. Same service on replacement infrastructure. Confidence: Medium. No later seizure recorded.[[3]](#source-3)

Indicators associated with the operation reappeared within days of the seizure and the developer publicly acknowledged the disruption while continuing to operate.

May 2025

Lumma replacement domains (3 domains, seized same wave). Same operators. Confidence: High. Seized in a later action.[[4]](#source-4)

Operators registered three replacement domains within approximately one day of the initial seizure; DOJ/Microsoft seized those as well within the same action window.

Return class B. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. [How this index handles it](https://takedownindex.org/about).

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[US Department of Justice statement on the seizure of Lumma Stealer command infrastructure](https://takedownindex.org/sources/united-states-department-of-justice-us-department-of-justice-statement-on-the-se)

United States Department of Justice, May 21, 2025, Source grade P1

Seizure of the central command structure and the marketplaces selling the malware

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

2.
[Europol statement on the Lumma Stealer disruption](https://takedownindex.org/sources/europol-europol-statement-on-the-lumma-stealer-disruption)

Europol, May 21, 2025, Source grade P2

Suspension of Europe-based infrastructure

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

### Additional reporting and technical analysis

1.
[Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool](https://takedownindex.org/sources/microsoft-on-the-issues-disrupting-lumma-stealer-microsoft-leads-global-action-a)

Microsoft On the Issues, May 21, 2025, Source grade T1

Court order, approximately 2,300 domains seized, more than 394,000 infected computers identified between 2025-03-16 and 2025-05-16, partner roles

[Open source](https://blogs.microsoft.com/on-the-issues/2025/05/21/microsoft-leads-global-action-against-favored-cybercrime-tool/)
2.
[Lumma Stealer operators register replacement domains within a day of seizure](https://takedownindex.org/sources/aggregated-security-reporting-lumma-stealer-operators-register-replacement-domai)

Aggregated security reporting, May 22, 2025, Source grade S1

Establishes that Lumma operators stood up three replacement domains within roughly a day of the initial May 2025 seizure, which DOJ/Microsoft subsequently also seized.

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note.
- Microsoft reported identifying more than 394,000 infected Windows computers globally between 2025-03-16 and 2025-05-16.
- PROBABLE EDGE CASE on the private-action exclusion. Included because DOJ seized infrastructure under criminal process alongside the civil order; a purely civil Microsoft action would have been excluded.

Research context

## How this entry was checked

This entry went through a dedicated source verification pass. Publisher, title, publication date, and docket numbers were confirmed against each cited source.

Source review: Verified core

Sources cited: 4

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Garantex disruption](https://takedownindex.org/takedowns/garantex-disruption)
- [HeartSender takedown](https://takedownindex.org/takedowns/heartsender-takedown)
- [GRU DNS-hijacking router network disruption (APT28)](https://takedownindex.org/takedowns/gru-dns-hijacking-router-network-disruption-apt28)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
