By visiting our site, you agree to our privacy policy regarding cookies, tracking statistics, etc.
Apply now for the new Geopolitics of Digital Infrastructure online live course
Apply now for the Geopolitics of Digital Infrastructure course
Read our new Monthly Cyber & Tech Digest in Substack
Monthly Cyber & Tech Digest now in in Substack
Apply now for free support from our Cybersecurity Services Centre
Apply for free cybersecurity support
From May 16-21, Microsoft’s Digital Crimes Unit, with U.S. and European authorities, carried out a takedown of the Lumma Stealer infostealer infrastructure. Following a U.S. court order, Microsoft seized and helped block ~2,300 domains used to distribute the Lumma malware. Lumma Stealer (malware-as-a-service) had infected ~394,000 Windows computers globally and was being used by multiple ransomware groups to steal credentials for follow-on attacks. The operation (“Disrupting Lumma”) significantly hampered the malware’s reach, though criminals later attempted to reconstitute their infrastructure.