The U.S. Department of Justice has shut down the LummaC2 malware infrastructure, which had stolen crypto assets wallet mnemonic phrases.

robot
Abstract generation in progress

On May 22, Decrypt reported that law enforcement has successfully seized the critical infrastructure of LummaC2, a malware that has committed mnemonic theft of cryptocurrency wallets against millions of users. The operation was jointly carried out by the U.S. Department of Justice, Europol, Japan’s Cybercrime Control Center, Microsoft and others.

According to Microsoft, more than 394,000 Windows systems worldwide were found to be infected with the malware between March and May 2025. Microsoft has seized and disabled more than 2,300 domains that support LummaC2’s operations through a civil lawsuit. The FBI confirmed that at least 1.7 million theft attempts occurred through LummaC2 alone.

Launched in 2022 by a Russian developer with the screen name “Shamel,” the malware is primarily marketed via Telegram and Russian-language forums, offering tiered service packages that allow buyers to customize, distribute, and track the stolen data.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)