Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Mar 20, 2025 | Updated Sep 17, 2025

Trojan:JS/LummaStealer

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

Trojan:JS/LummaStealer is a complex Javascript-based Malware-as-a-Service (MaaS) that is used for information-stealing purposes. Threat actors can rent access to this tool for yearly subscriptions that range from $250 to $1,000, lowering barriers for cyberattack operation. 

Trojan:JS/LummaStealer spreads through social engineering, with the main vector relying on enticing fake CAPTCHA verification pages to trick users to download and run the malicious code on their device. The LummaStealer script has an extensive capturing toolset to harvest a variety of sensitive information from target devices, including, but not limited to, web browser credentials, cryptocurrency wallets, and other personally identifiable information. In mid-2025, a major enforcement operation arrested many of these threat actors and disrupted their infrastructure, following an extensive law enforcement operation in which Trojan:JS/LummaStealer was discovered to have infected hundreds of thousands of Windows computers across various industries, including finance, healthcare, and telecommunications. 

  • Disconnect all impacted devices from your networks. 
  • Initiate a forced password reset of all impacted user and service accounts starting with the domain administrator account(s) and other high privilege credentials.  
  • Reboot the system into Safe Mode with Networking to prevent most malware processes from loading and to allow for cleaning. 
  • Consider a complete rebuild of the operating system from trusted media for severe infections, as this is the only way to guarantee the system is clean. 

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. 

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help. 

Follow us