By visiting our site, you agree to our privacy policy regarding cookies, tracking statistics, etc.
Apply to join the new European Cybersecurity PhD Accelerator. Limited places available now!
Apply to join the new European Cybersecurity PhD Accelerator
Read our new Monthly Cyber & Tech Digest in Substack
Monthly Cyber & Tech Digest now in in Substack
Apply now for free support from our Cybersecurity Services Centre
Apply for free cybersecurity support
From May 16-21, Microsoft’s Digital Crimes Unit, with U.S. and European authorities, carried out a takedown of the Lumma Stealer infostealer infrastructure. Following a U.S. court order, Microsoft seized and helped block ~2,300 domains used to distribute the Lumma malware. Lumma Stealer (malware-as-a-service) had infected ~394,000 Windows computers globally and was being used by multiple ransomware groups to steal credentials for follow-on attacks. The operation (“Disrupting Lumma”) significantly hampered the malware’s reach, though criminals later attempted to reconstitute their infrastructure.