Skip to main content

Microsoft and authorities take action against Lumma Stealer

Microsoft announced legal and technical actions against Lumma Stealer, a malware dedicated to stealing information from browsers, applications and wallets.

CybersecuritySeintec team2-3 min read
Microsoft and authorities take action against Lumma Stealer

News summary

Microsoft announced legal and technical actions against Lumma Stealer, a malware dedicated to stealing information from browsers, applications and wallets. The operation aimed to block domains and infrastructure used by the campaign.

Infostealers turn a local infection into an identity problem. EDR, web filtering, equipment updates and rapid credential rotation help break the chain.

Source: Reuters — 21 May 2025

What happened

In May 2025 Microsoft announced legal and technical action against Lumma Stealer, malware dedicated to stealing information stored in browsers, applications and cryptocurrency wallets. The operation sought to block domains and infrastructure used by the campaign, coordinated with other industry entities.

Lumma Stealer spread through varied infection campaigns and mainly worked as a tool to extract saved credentials, session cookies and wallet data, which were then sold or used for further attacks.

What it means for a mid-sized business

This kind of malware turns a seemingly minor local infection into an identity problem: stolen credentials are reused to access company email, VPN or cloud applications, often without needing to breach anything else.

Microsoft's action reduces infrastructure used by one specific actor, but it does not eliminate the technique. Any device without adequate protection can be infected by similar variants and become the entry point into corporate systems.

What to review

Measures that cut the chain between infection and account compromise:

  • Updated endpoint protection (EDR) on every device, including remote-work machines.
  • Web filtering that blocks download domains known to distribute malware.
  • Credential rotation and closing active sessions when infection is suspected.
  • Two-factor authentication resistant to session-cookie theft on critical access points.

Frequently Asked Questions

What exactly does Lumma Stealer steal?
Credentials saved in browsers, session cookies, cryptocurrency wallet data and other information stored locally on the infected device.
Did Microsoft's action eliminate the threat?
It reduced infrastructure used by the campaign, but this type of malware tends to reappear with new infrastructure or similar variants.
What can a small business do to protect itself?
Keep endpoint protection up to date, avoid downloads from unverified sources and use session-theft-resistant two-factor authentication on the most sensitive access points.

Concepts mentioned in this article: Malware

Is your company prepared for an incident of this type? At Seintec we can review access, backups, cloud, endpoints and procedures to reduce exposure and recovery times. Let’s talk.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.