CybersecuritySecurity

Lumma Stealer Malware Operation Disrupted by Doxxing Campaign and Infrastructure Takedowns

Core developers behind the notorious Lumma Stealer malware have been doxxed, with sensitive personal information leaked online. The operation has suffered significant disruptions including compromised Telegram accounts and reduced infrastructure activity, according to security analysts.

Malware Developers Exposed in Coordinated Doxxing Campaign

The development team behind Lumma Stealer, one of the most prominent information-stealing malware families, has been targeted in an extensive doxxing campaign that leaked sensitive personal information of core members, according to a Trend Micro analysis. The campaign, which occurred between August and October 2025, exposed passport numbers, bank account details, email addresses, and online profiles of five individuals allegedly responsible for malware development and administration.