CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Law Enforcement Seize Domains Linked to Seed Phrase Stealing Malware LummaC2
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Law Enforcement Seize Domains Linked to Seed Phrase Stealing Malware LummaC2
News

Law Enforcement Seize Domains Linked to Seed Phrase Stealing Malware LummaC2

CoinRSS
Last updated: May 22, 2025 3:57 pm
CoinRSS Published May 22, 2025
Share

Contents
In briefMalware on the declineEvolving theftDaily Debrief Newsletter

In brief

  • The U.S. and international authorities have seized key infrastructure tied to the LummaC2 info-stealer
  • The malware targets information such as crypto wallet seed phrases
  • Lumma is linked to over 1.7 million theft attempts and active in 394,000 global infections, according to Microsoft

Law enforcement agencies have seized key infrastructure linked to LummaC2, a malware operation that targeted millions of victims worldwide, including by stealing crypto wallet seed phrases, according to a U.S. Department of Justice announcement on Wednesday.

The seizures were part of a coordinated international effort involving the DOJ, Europol, Japan’s Cybercrime Control Center, Microsoft, and private cybersecurity partners.

Following the initial DOJ seizure of two websites on May 19, Lumma administrators scrambled to establish three new domains, only to have those seized the next day. 

Microsoft additionally identified over 394,000 infections on Windows systems globally between March and May 2025. Through a civil action filed earlier this month, Microsoft’s Digital Crimes Unit seized and disabled over 2,300 domains supporting Lumma’s infrastructure.

“Malware like LummaC2 is deployed to steal sensitive information such as user login credentials from millions of victims in order to facilitate a host of crimes, including fraudulent bank transfers and cryptocurrency theft,” said Matthew R. Galeotti, head of the DOJ’s Criminal Division, in a statement.

Malware on the decline

Malware isn’t as popular as it once was.

According to CrowdStrike’s 2025 Global Threat Report, there has been a shift towards malware-free attacks over the past five years as attackers move to stealthier methods such as phishing, social engineering, access broker services, and trusted relationship abuse.

Last year, 79% of attacks it detected were malware-free, compared to 40% in 2019.

Nevertheless, that doesn’t mean there aren’t willing buyers for Malware-as-a-Service tools like Lumma, which allow relatively unsophisticated threat actors to access advanced capabilities.

The FBI has identified its use in at least 1.7 million theft attempts using Lumma alone. 

Crypto wallets are common targets. Earlier this month, researchers identified fake AI bots spreading malware targeting crypto traders, while Inferno Drainer has stolen more than $9 million from wallets over the last six months.

Evolving theft

Launched in around 2022, Lumma has evolved through multiple iterations and is controlled by a Russian developer known online as “Shamel.”

Operating openly via Telegram and Russian-language forums, Shamel markets Lumma in tiered service packages that allow buyers to customize, distribute, and track stolen data.

One notable campaign using Lumma involved fake emails impersonating Booking.com used to steal login credentials and empty bank accounts.

The malware has also been linked to attacks on education systems, gaming communities, and critical infrastructure sectors, including healthcare and logistics. Its stealth and flexibility have made it a favored tool among high-profile ransomware groups such as Octo Tempest.

Microsoft said it was continuing to monitor emerging variants of Lumma, warning that the malware remains a potent threat even as its core infrastructure is being dismantled.

Edited by Sebastian Sinclair

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

AAVE drops below $200, but smart traders are accumulating- Why?

High FUD, 73% longs – Is Cardano’s $0.50 support hanging by a thread?

Polygon nears $100B volume mark – Factors that will help POL

Analysts call SEC’s ETF delay ‘expected’—But is approval likely?

Here’s Every Crypto Firm That Shelled Out for Trump’s Inauguration

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article NYC mayor Eric Adams launches advisory council to ‘use tech of tomorrow’
Next Article Dogecoin eyes $0.239 – Here’s what can help DOGE’s breakout
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Kraken to Offer Tokenized Stock Trading on Solana to Overseas Customers
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?