osec.one case analysis cover: Lumma Stealer, fake CAPTCHAs and the 2025 takedown

Most account takeovers no longer start with someone guessing a password. They start with a file of passwords and session cookies copied from a real person's computer, bought for a few dollars. For about two years the most common source of those files was one product: Lumma Stealer, also called LummaC2.

The FBI called it "the most popular infostealer service available in online criminal markets". This is how the service was run, how its best-known lure works, what happened when Microsoft and police in several countries took it down in May 2025, and what any of it means if you run a website with a sign-in page.

Attack chain: a criminal rents Lumma from 250 dollars a month, a compromised site or advert shows a fake CAPTCHA, the page copies a command to the clipboard and asks the visitor to paste it into the Windows Run box, the stealer runs once and collects saved passwords, cookies and wallets, the log is uploaded and sold, the buyer replays a session cookie and is signed in
The person at the keyboard runs the malware. Nothing has to be exploited.

The business: malware you rent

Lumma appeared on Russian-language forums in 2022. Its developer, known as "Shamel" (Microsoft tracks him as Storm-2477), didn't infect anyone himself. He sold access to the malware and a web panel for managing what it stole. Microsoft's court filing lists the plans:

• Experienced, $250: the stealer, a build tool and the log panel.
• Professional, $500 and Corporate, $1,000: more ways to hide the file from antivirus and to sort the stolen data.
• Source, $20,000: the code itself, with the right to resell it.

In a November 2023 interview Shamel said he had about 400 active clients. Each client (an "affiliate") chooses how to spread the file and keeps what it steals. That split is why Lumma turned up in so many unrelated campaigns: the people spreading it had nothing in common but the subscription. Microsoft names Octo Tempest, the group also called Scattered Spider, among the customers.

The lure: a CAPTCHA that asks you to press Win+R

Affiliates used every channel there is: phishing emails (one March 2025 campaign posed as Booking.com), adverts placed above search results for popular software, cracked programs, fake game cheats on GitHub and YouTube. The one that grew fastest is known as ClickFix, and it needs no software flaw at all.

Step by step

1. A visitor lands on a page with a familiar box: "I'm not a robot". The page may be a site built for the purpose, or a real site that was broken into and had a script added.
2. Clicking the box copies a command to the clipboard. The visitor doesn't see this happen.
3. The page then shows "verification steps": press Windows+R, press Ctrl+V, press Enter.
4. Windows+R opens the Run box. The pasted text is a one-line command that starts a built-in Windows program (Microsoft saw mshta; others report PowerShell), which downloads and runs the stealer.
5. The command usually ends with harmless-looking text along the lines of "I am not a robot - reCAPTCHA Verification ID" and a number, so the short Run box shows only that part.

The trick works because each key press feels like part of a test, and because the person, not the browser, starts the download. Browser warnings and download scanning never get a say. ESET counted 517% more of these fake error and fake CAPTCHA pages in the first half of 2025 than in the half-year before, enough to make it the second most common attack method it blocked, after phishing.

No real CAPTCHA has ever asked anyone to open the Run box, a terminal or PowerShell. That one sentence is worth teaching to everyone you work with.

Your site can be the page that shows it

Site owners are on both ends of this. Microsoft describes ordinary websites, compromised through a plugin or a stolen admin login, that had JavaScript added to show the fake box to their visitors. In some cases the added script kept its real instructions in a public blockchain record and fetched them at load time, so there was nothing obviously bad in the page source. A content security policy that lists where scripts may come from, with reporting turned on, is one of the few controls that notices a script nobody on the team added. osec CSP Reports collects those reports without any change to your DNS.

What one run collects

A stealer doesn't stay on the machine. It runs once, gathers, uploads and is done. Microsoft lists what Lumma looks for:

• Browsers (Chrome, Edge, Firefox and relatives): saved passwords, session cookies and autofill data, which includes addresses and saved cards.
• Cryptocurrency wallets and wallet browser extensions such as MetaMask, Electrum and Exodus.
• Other apps: VPN profiles (.ovpn files), email clients, FTP clients, Telegram.
• Documents from user folders: .pdf, .docx, .rtf.
• A description of the machine: processor, Windows version, language, installed programs.

All of it goes into one bundle per machine, called a log. The last item matters more than it looks. A buyer who knows the victim's browser, language and screen can make their own browser look the same, which gets past many "is this a new device?" checks.

Chrome made cookie theft harder in mid-2024 by tying its cookie encryption to the Chrome program itself. Elastic Security Labs recorded Lumma and its rivals working around the change within a few months. On a PC where malware runs as the signed-in user, the browser can't keep secrets from it for long.

From log to account takeover

Logs are sold in bulk on markets and Telegram channels, searchable by website. A buyer who wants access to one company searches for its sign-in address and buys the matching logs. Then there are two ways in:

• The password, if the account has no second step. This is what happened at Snowflake's customers in 2024, with logs up to four years old.
• The session cookie, if it's still valid. The buyer loads it into their own browser and is signed in. No password prompt, no code, no passkey, because the sign-in already happened on the victim's machine.

We went through the cookie route in detail in session cookie theft after MFA. The point here is scale: the FBI counted at least 1.7 million cases of Lumma being used to steal this kind of data.

The takedown, May 2025

Between 16 March and 16 May 2025 Microsoft counted more than 394,000 Windows computers infected with Lumma. On 13 May its Digital Crimes Unit filed a civil case in the US District Court for the Northern District of Georgia. What followed, announced on 21 May:

• About 2,300 domains that the malware used to reach its operators were seized, suspended or blocked.
• More than 1,300 of them were pointed at Microsoft's own servers ("sinkholes"), so infected PCs reported to Microsoft, not to criminals. Europol helped with about 300 of those.
• The US Justice Department seized the five domains that ran the customer panels: two on 19 May, then three more on 21 May, a day after the operators registered them as replacements.
• Europol's cybercrime centre and Japan's JC3 acted against infrastructure in their regions. Cloudflare, ESET, Lumen, BitSight and others took part.

It was a well-run operation, and the three-domain detail shows why it wasn't final: the operators had new panels up within a day.

What happened next

• 24 May 2025: the developer posts that police got into his main server through a flaw in its remote management controller, and that he has control again. Nobody was arrested.
• June and July: Trend Micro's count of accounts targeted by Lumma "steadily returned to their usual levels". The operators moved away from Cloudflare, which had helped the takedown, towards hosting in Russia, and affiliates went back to fake cracks, ClickFix pages and GitHub repositories with machine-written README files.
• Late August to October: a site called "Lumma Rats" publishes names, passwords and financial records of five people it says run the service. Trend Micro thinks rivals were behind it.
• 17 September: Lumma's Telegram accounts are reported taken over. New control servers and infected machines drop sharply that month.

So the police action cost Lumma a few weeks, and exposure of the people behind it appears to have cost it far more. Its customers didn't retire. Trend Micro saw other stealer sellers competing hard for them. For a defender the name on the malware changes very little: the log has the same contents whoever built the tool.

What a site owner can do

You can't clean your customers' computers. You can decide how much a log stolen from one of them is worth on your site.

Store less that can be stolen

• A password saved in a browser is the longest-lived item in a log. If your sign-in is a one-time code by email, or Google or Apple, there is no password of yours in the log to buy.
• Don't let an old session be the only thing between a visitor and a damaging action. Ask for a fresh sign-in before changing the email address, adding a payout account or exporting data.

Make a copied session expire or stand out

• Keep sessions short for accounts that can do harm: hours for admins, not a month.
• Replace the session token on each sign-in and at intervals, and end every session when the password or email changes.
• Record a rough picture of the device at sign-in (browser family, platform, network owner). When the same session shows up with a different picture, ask for sign-in again. The copy won't always differ, because the log describes the victim's machine, but careless buyers are common.

Give people a way to see and end sessions

• A "where you're signed in" list with a "sign out everywhere" button costs a day to build and is the first thing an infected user needs.
• Email the account owner when a new device signs in, with that button in the email.

Inside your own team

• Tell everyone the Run-box sentence above. It takes one minute.
• On work PCs that don't need it, switch off the Run box (Group Policy: "Remove Run menu from Start Menu") and limit mshta and PowerShell for ordinary users.
• No work sign-ins from a family computer where games and cracked software get installed. That is how the logs behind Snowflake and Uber started.
• If a PC was infected, cleaning it isn't the end. End every session and change every password that browser held, from another device.

The lesson

Lumma showed that stealing sign-ins is now a subscription anyone can buy, and that removing one seller's servers moves the customers, not the trade. Assume some of your users' browsers have been copied. The useful question is what the copy lets a stranger do on your site, and for how long.

osec Auth adds passwordless sign-in to your site: email code, Google and Apple, with no OAuth setup on your side. No saved password of yours for a stealer to find.

Add passwordless sign-in

Sources: Microsoft On the Issues: Disrupting Lumma Stealer (21 May 2025); Microsoft Threat Intelligence: Lumma Stealer, breaking down the delivery techniques and capabilities; US Department of Justice: Justice Department seizes domains behind major information-stealing malware operation; Trend Micro: Back to business, Lumma Stealer returns with stealthier methods; Trend Micro: The impact of Water Kurita (Lumma Stealer) doxxing; Infosecurity Magazine: ClickFix attacks surge 517% in 2025 (ESET H1 2025 threat report); Elastic Security Labs: Katz and mouse game, MaaS infostealers adapt to patched Chrome defenses.