Microsoft Disrupts Global Cybercrime Tool, Secures Estimated 394,000 Infected Computers

Microsoft's Digital Crimes Unit (DCU) has taken down the preferred malware used by hundreds of cyber threat actors to indiscriminately steal sensitive personal and organizational information. On May 13, Microsoft filed a legal action against Lumma Stealer, a malware used for financial fraud, theft, and ransomware attacks. The action involved a court order to seize and facilitate the takedown, suspension, and blocking of approximately 2,300 malicious domains forming the backbone of Lumma's infrastructure. This move, in collaboration with international partners, has significantly disrupted the operations of cybercriminals.

Key Takeaways:

  • Microsoft's Digital Crimes Unit (DCU) filed a legal action against Lumma Stealer, a preferred malware used by hundreds of cyber threat actors, on May 13.
  • The malware, used for financial fraud, theft, and ransomware attacks, has enabled criminals to hold schools for ransom, empty bank accounts, and disrupt critical services.
  • Microsoft's DCU, in collaboration with international partners, seized and facilitated the takedown, suspension, and blocking of approximately 2,300 malicious domains that formed the backbone of Lumma's infrastructure.
  • The Department of Justice (DOJ) simultaneously seized the central command structure for Lumma, disrupting the marketplaces where the tool was sold to other cybercriminals.
  • Europol's European Cybercrime Center (EC3) and Japan's Cybercrime Control Center (JC3) facilitated the suspension of locally based Lumma infrastructure.
  • Between March 16, 2025, and May 16, 2025, Microsoft identified over 394,000 Windows computers globally infected by the Luma malware.
  • Working with law enforcement and industry partners, Microsoft severed communications between the malicious tool and victims, including redirecting more than 1,300 domains seized or transferred, including 300 domains actioned by law enforcement, to Microsoft sinkholes.
  • The joint action is designed to slow the speed at which cybercriminals can launch their attacks, minimize the effectiveness of their campaigns, and hinder their illicit profits by cutting a major revenue stream.

Statistics:

  • Over 394,000 Windows computers globally were infected by the Luma malware between March 16, 2025, and May 16, 2025.
  • 2,300 malicious domains that formed the backbone of Lumma's infrastructure were seized and suspended.
  • 1,300 domains were seized or transferred, including 300 domains actioned by law enforcement, and were redirected to Microsoft sinkholes.
  • 400 active clients for the Lumma malware service were reported by its primary developer in November 2023.

Sources:

  • Microsoft -- Disrupting the tools cybercriminals frequently use can create a significant and lasting impact on cybercrime.
  • Darktrace -- The Rise of MaaS & Lumma Info Stealer
  • Microsoft -- Phishing campaign impersonates Booking.com, delivers a suite of credential-stealing malware
  • ESET -- Luma Stealer Malware Disrupts Operations of Hundreds of Cyber Threat Actors