Table of Contents
This updated guide explores lumma malware infected more than 394,000 Windows pcs with practical details, clear explanations, and useful takeaways. In a new blog post, Microsoft has released some troubling malware numbers. The company warns that Lumma — a piece of information-stealing malware — has infected more than 394,000 Windows systems globally in just two months, from March 16, 2025 to May 16, 2025.
According to Microsoft, Lumma Stealer (also known as LummaC2 ) is a malware-as-a-service (MaaS) developed by the Storm-2477 hacker group. Hackers have used Lumma to steal sensitive data from applications such as browsers, cryptocurrency wallets, and many other sources.
The tech giant also explained how Lumma is distributed through malicious campaigns including:
- Phishing Email
- Malvertising
- Drive-by downloads from compromised websites
- Fake apps contain malware
- Fake CAPTCHAs Fool Users
for instance, in the case of malvertising , Microsoft points out that fake ads such as 'Download Notepad++' or 'Update Chrome' are used to lure victims. To avoid this trap, users should download applications only from the developer's official website . Still, the risk does not stop there. Even when downloading the browser from a safe source, Lumma can still infiltrate the system through other methods. After a successful infection, Lumma can steal data from both Chromium-based browsers (Chrome, Edge) as well as Gecko-based browsers (Firefox).
Microsoft details Lumma's malicious capabilities as follows:
- Browser and cookie information : Extract saved passwords, session cookies, autofill data from Chromium, Edge, Firefox.
- Cryptocurrency Wallets and Extensions : Search for wallet files, browser extensions, and local keys related to MetaMask, Electrum, Exodus.
- Diverse applications : Steal data from VPN (.ovpn), email applications, FTP, Telegram.
- User Documents : Collect PDF, DOCX, RTF files from personal folders.
- System Information : Collect data such as CPU, OS version, installed applications to customize attacks later.
In the heat map below, Microsoft shows Lumma's wide reach, concentrated in Europe, the eastern United States, and parts of India :

There is some good news, though. Microsoft claims that Defender — its antivirus engine — was able to detect LummaC2 through warnings flagging it as a Trojan or displaying these suspicious behavior:
- Behavior:Win32/LuammaStealer
- Trojan:JS/LummaStealer
- Trojan:MSIL/LummaStealer
- Trojan:Win32/LummaStealer
- Trojan:Win64/LummaStealer
- TrojanDropper:Win32/LummaStealer
- Trojan:PowerShell/Powdow
- Trojan:Win64/Shaolaod
- Behavior:Win64/Shaolaod
- Behavior:Win32/MaleficAms
- Behavior:Win32/ClickFix
- Behavior:Win32/SuspClickFix
- Trojan:Win32/ClickFix
- Trojan:Script/ClickFix
- Behavior:Win32/RegRunMRU
- Trojan:HTML/FakeCaptcha
- Trojan:Script/SuspDown
Defender for Office 365 and Defender for Endpoint are also getting similar detection updates. You can see technical details about Lumma in the official posts from Microsoft.
FAQ
What is the main takeaway about Lumma Malware Infected More Than 394,000 Windows PCs?
The key is to understand the core idea, compare the available options, and apply the practical guidance that matches your situation.
What should beginners know about Lumma Malware Infected More Than 394,000 Windows PCs?
Start with the essential steps and terminology. Avoid changing advanced settings until you understand how they affect performance, privacy, cost, or compatibility.
How can I use this information in practice?
Follow the relevant section in order, test one change at a time, and confirm the result before moving to the next step or recommendation.
Reader Comments 0
Sign in with email or Google to join the discussion.