Key points of this blogpost: ESET took part in a coordinated global operation to disrupt Lumma Stealer. Lumma Stealer identifierEach Lumma Stealer sample contains a unique hardcoded affiliate identifier known as LID. Lumma Stealer C&C communication flowAnti-analysis obfuscation techniquesLumma Stealer employs a few, but effective, anti-emulation techniques to make analysis as complicated as possible. The disruption operation, led by Microsoft, aims to seize all known Lumma Stealer C&C domains, rendering Lumma Stealer’s exfiltration infrastructure nonfunctional. ESET will continue to track other infostealers while closely monitoring for Lumma Stealer activity following this disruption operation.