
Authorities Carry Out Elaborate Global Takedown of Infostealer Heavily Used by Cybercriminals
Lily Hay Newman, Matt Burgess
created: May 21, 2025, 4 p.m. | updated: May 24, 2025, 11:21 a.m.
A consortium of global law enforcement agencies and tech companies announced on Wednesday that they have disrupted the infostealer malware known as Lumma.
At the same time, the US Department of Justice seized Lumma’s command-and-control infrastructure and disrupted cybercriminal marketplaces that sold the Lumma malware.
All of this was coordinated, too, with disruption of regional Lumma infrastructure by Europol’s European Cybercrime Center and Japan’s Cybercrime Control Center.
Microsoft says that more than 394,000 Windows computers were infected with the Lumma malware between March 16 and May 16 this year.
“Cloudflare’s role in the disruption included blocking the command-and-control server domains, Lumma’s Marketplace domains, and banning the accounts that were used to configure the domains,” the company wrote in a blog post on Wednesday.
2 weeks, 3 days ago: WIRED