DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-29
malware

LummaC2 Infostealer

EXECUTIVE INTELLIGENCE SUMMARY

Pervasive commodity infostealer harvesting session tokens, cryptocurrency wallet private keys, browser passwords, and MFA cookies across global consumer and corporate endpoints.

Written in pure C with extensive anti-VM and anti-analysis tricks (control flow flattening, Heaven’s Gate API resolution). Relies on Telegram C2 channels and compromised CDN networks for rapid exfiltration of OAuth session databases.

SOURCE CITATIONS & ATTESTATIONS (1)
Mandiant Infostealer Ecosystem CensusMandiant

The Proliferation of Token-Theft Infostealers

TELEMETRY CARDID: malware-lummac2
ENTITY TYPE
malware
INDEXED TAGS
#infostealer#credential_harvesting#token_theft#c2