Europol and Microsoft disrupt world’s largest infostealer Lumma


Europol’s European Cybercrime Centre has worked with Microsoft to disrupt Lumma Stealer (“Lumma”), the world’s most significant infostealer threat.

This joint operation targeted the sophisticated ecosystem that allowed criminals to exploit stolen information on a massive scale. Europol coordinated with law enforcement in Europe to ensure action was taken, leveraging intelligence provided by Microsoft. Between 16 March and 16 May 2025, Microsoft identified over 394 000 Windows computers globally infected by the Lumma malware. In a coordinated follow-up operation this week, Microsoft’s Digital Crimes Unit (DCU), Europol, and international partners have disrupted Lumma’s technical infrastructure, cutting off communications between the malicious tool and victims.

Read more…
Source: Europol


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Cybercrime: Ransomware remains a ‘key’ malware threat says Europol

    September 18, 2018

    Targeted attacks replace spam campaigns, but Europol’s annual cybercrime report also warns that cryptojacking malware “may overtake ransomware as a future threat”. Ransomware remains the top malware threat to organisations, causing millions of dollars of damage and remaining a potent tool for cyber criminals and nation-state attackers. The rise of highly targeted file-locking malware campaigns and the ...

  • Government mass surveillance breached human rights, says European court

    September 13, 2018

    Mass surveillance and data collection programs used by the UK government breached privacy and don’t meet the necessary legal requirements to guarantee rights will be upheld, the European Court of Human Rights (ECHR) has ruled. The court has concluded that the UK’s mass interception programmes breached the European Convention on Human Rights. The case of ‘Big ...

  • Russian domestic security service launch new dedicated center to counter cyberattacks

    September 11, 2018

    Russia’s Federal Security Service, the FSB, now has a separate coordination center created in order to prevent, detect and counter cyberattacks on critical infrastructure facilities as well as repair damage from such attacks. The new agency is officially titled ‘National Coordination Center for Computer Incidents’ and it will be headed by Andrey Ivashko who is also ...

  • Spyware firm SpyFone leaves customer data, recordings exposed online

    August 24, 2018

    Spyware is morally dubious software, and yet, business is booming. This particular form of malware comes in various forms including keyloggers, modular software capable of taking screenshots, malicious code able to view and steal content such as photos and videos, as well as recorders of text messages, phone calls, and browser histories. It is not just government entities or ...

  • EU considers 60-minute deadline for social networks to remove terrorist content

    August 20, 2018

    No longer the carrot, now the stick: the European Commission is considering imposing an hour-long deadline for social networks to remove terrorist and extremist content after voluntary measures appear to have failed. As reported by the Financial Times on Sunday, Facebook, Twitter, and YouTube, as well as smaller businesses, are all within the EU’s sights. This is the first ...

  • FBI Warns Of ATM Hacking Campaign

    August 16, 2018

    The FBI has warned banks that cybercriminals are preparing to carry out a “highly choreographed, global fraud scheme known as an ‘ATM cash-out’.” The threat, reported by Krebs On Security cybersecurity blog, will apparently see criminals hacking a bank or payment card processor, and using cloned cards at ATMs around the world to fraudulently withdraw “millions of ...