Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Dyson’s new stain-spotting AI robovac is now available

    Dyson’s new stain-spotting AI robovac is now available

    March 12, 2026
    Anthropic doesn’t trust the Pentagon, and neither should you

    Anthropic doesn’t trust the Pentagon, and neither should you

    March 12, 2026
    You can now ask Google Maps ‘complex, real-world questions’ — and Gemini will answer

    You can now ask Google Maps ‘complex, real-world questions’ — and Gemini will answer

    March 12, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals
    Security

    Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals

    News RoomBy News RoomMay 22, 20254 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals

    Some infostealer operators bundle and sell this stolen data. But increasingly the compromised details have acted as a gateway for hackers to launch further attacks, providing them with the details needed to access online accounts and the networks of multibillion-dollar corporations.

    “It’s clear that infostealers have become more than just grab-and-go malware,” says Patrick Wardle, CEO of the Apple device-focused security firm DoubleYou. “In many campaigns they really act as the first stage, collecting credentials, access tokens, and other foothold-enabling data, which is then used to launch more traditional, high-impact attacks such as lateral movement, espionage, or ransomware.”

    The Lumma infostealer first emerged on Russian-language cybercrime forums in 2022, according to the FBI and CISA. Since then its developers have upgraded its capabilities and released multiple different versions of the software.

    Since 2023, for example, they have been working to integrate AI into the malware platform, according to findings from the security firm Trellix. Attackers want to add these capabilities to automate some of the work involved in cleaning up the massive amounts of raw data collected by infostealers, including identifying and separating “bot” accounts that are less valuable for most attackers.

    One administrator of Lumma told 404Media and WIRED last year that they encouraged both seasoned hackers and new cybercriminals to use their software. “This brings us good income,” the administrator said, referring to the resale of stolen login data.

    Microsoft says that the main developer behind Lumma goes by the online handle “Shamel” and is based in Russia.

    “Shamel markets different tiers of service for Lumma via Telegram and other Russian-language chat forums,” Microsoft’s Masada wrote on Wednesday. “Depending on what service a cybercriminal purchases, they can create their own versions of the malware, add tools to conceal and distribute it, and track stolen information through an online portal.”

    Kela’s Kivilevich says that in the days leading up to the takedown, some cybercriminals started to complain on forums that there had been problems with Lumma. They even speculated that the malware platform had been targeted in a law enforcement operation.

    “Based on what we see, there is a wide range of cybercriminals admitting they are using Lumma, such as actors involved in credit card fraud, initial access sales, cryptocurrency theft, and more,” Kivilevich says.

    Among other tools, the Scattered Spider hacking group—which has attacked Caesars Entertainment, MGM Resorts International, and other victims—has been spotted using the Lumma stealer. Meanwhile, according to a report from TechCrunch, the Lumma malware was allegedly used in the buildup to the December 2024 hack of education tech firm PowerSchool, in which more than 70 million records were stolen.

    “We’re now seeing infostealers not just evolve technically, but also play a more central role operationally,” says DoubleYou’s Wardle. “Even nation-state actors are developing and deploying them.”

    Ian Gray, director of analysis and research at the security firm Flashpoint, says that while infostealers are only one tool that cybercriminals will use, their prevalence may make it easier for cybercriminals to hide their tracks. “Even advanced threat actor groups are leveraging infostealer logs, or they risk burning sophisticated tactics, techniques, and procedures,” Gray says.

    Lumma isn’t the first infostealer to be targeted by law enforcement. In October last year, the Dutch National Police, along with international partners, took down the infrastructure linked to the RedLine and MetaStealer malware, and the US Department of Justice unsealed charges against Maxim Rudometov, one of the alleged developers and administrators of the RedLine infostealer.

    Despite the international crackdown, infostealers have proven too useful and effective for attackers to abandon. As Flashpoint’s Gray puts it, “Even if the landscape ultimately shifts due to the evolution of defenses, the growing prominence of infostealers over the past few years suggests they are likely here to stay for the foreseeable future. Usage of them has exploded.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleMicrosoft Notepad can now write for you using generative AI
    Next Article What in the world are Jony Ive and Sam Altman building?

    Related Posts

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    December 6, 2025
    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    December 5, 2025
    Your Data Might Determine How Much You Pay for Eggs

    Your Data Might Determine How Much You Pay for Eggs

    December 4, 2025
    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    December 4, 2025
    This Hacker Conference Installed a Literal Antivirus Monitoring System

    This Hacker Conference Installed a Literal Antivirus Monitoring System

    December 4, 2025
    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    December 4, 2025
    Our Picks
    Anthropic doesn’t trust the Pentagon, and neither should you

    Anthropic doesn’t trust the Pentagon, and neither should you

    March 12, 2026
    You can now ask Google Maps ‘complex, real-world questions’ — and Gemini will answer

    You can now ask Google Maps ‘complex, real-world questions’ — and Gemini will answer

    March 12, 2026
    One of Grammarly’s ‘experts’ is suing the company over its identity-stealing AI feature

    One of Grammarly’s ‘experts’ is suing the company over its identity-stealing AI feature

    March 11, 2026
    iPhone Fold rumor: iPad-like multitasking, but no iPad apps and no Face ID

    iPhone Fold rumor: iPad-like multitasking, but no iPad apps and no Face ID

    March 11, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    You can’t replace the battery in Lego’s Smart Bricks — and many of its sensors aren’t available yet News

    You can’t replace the battery in Lego’s Smart Bricks — and many of its sensors aren’t available yet

    By News RoomMarch 11, 2026

    The first Lego Smart Brick sets, based on Star Wars, aren’t quite what my kids…

    Microsoft’s next Xbox, Project Helix, won’t reach alpha until 2027

    Microsoft’s next Xbox, Project Helix, won’t reach alpha until 2027

    March 11, 2026
    Grammarly says it will stop using AI to clone experts without permission

    Grammarly says it will stop using AI to clone experts without permission

    March 11, 2026
    Microsoft’s ‘Xbox mode’ is coming to every Windows 11 PC

    Microsoft’s ‘Xbox mode’ is coming to every Windows 11 PC

    March 11, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.