216.73.216.6

Behind the Curtain: How Lumma Affiliates Operate

· Published 20/08/2025 18:39 · Modified 20/08/2025 21:21

Export JSON

Essential information

Published
20/08/2025 18:39
Modified
20/08/2025 21:21
Tags
2025-08-20 affiliate anti-detect browser craxsrat crypting cybercrime infostealer lumma meduza stealer proxy stealc underground forums vidar vpn
Related entities
1 intrusion sets (apt), 5 malware

Description

This analysis reveals the complex operations of affiliates within a vast information-stealing ecosystem. Affiliates utilize various tools and services, including networks, VPNs, anti-detect browsers, and services. The investigation uncovered previously undocumented tools and showed that affiliates often run multiple schemes simultaneously, such as rental scams, while also using other infostealers like , , and . affiliates are deeply integrated into the cybercriminal ecosystem, leveraging for resources, marketplaces, and operational support. The analysis highlights the resilience of 's infrastructure and the challenges in disrupting such decentralized cybercriminal networks.

External references