
Microsoft announced that it had successfully stopped the operation of the infamous Lumma Stealer malware. The tech giant revealed in a May 21 blog post that a federal court in Georgia authorized its Digital Crimes Unit to take legal action, resulting in the takedown or suspension of nearly 2,300 websites tied to the malware’s infrastructure.
Working closely with both local and international law enforcement agencies, including Europol’s European Cybercrime Center and Japan’s Cybercrime Control Center, Microsoft was able to dismantle large parts of the Lumma network. The U.S. Department of Justice also played a key role, seizing Lumma’s command-and-control servers and cracking down on underground marketplaces where the tool was being sold.
Lumma, first spotted in 2022, has evolved significantly over time. It’s a sophisticated piece of malware that enables cybercriminals to steal sensitive data—everything from passwords and banking info to crypto wallet details.

Source: Microsoft Blog
Between March 16 and May 16, this year, Microsoft discovered over 394,000 Windows systems infected with Lumma and worked with cybersecurity organizations and law enforcement to block the virus from communicating with those PCs.
A Broader Rise in Crypto-Related Threats
The crackdown comes amid a wider surge in crypto-related cybercrime. So-called “crypto drainers”—malicious software designed to empty crypto wallets—are increasingly popping up in phishing scams, fake browser extensions, and even disguised as legitimate software.
In a recent alarming incident, Chinese printer company Procolored reportedly bundled Bitcoin-stealing malware with its official drivers, causing users to lose nearly $1 million in crypto.
What’s more concerning is that these tools are becoming more accessible. An AMLBot report last month highlighted that crypto drainers are now available as a service, costing as little as $100, making it easier for even amateur hackers to exploit victims.
According to Chainalysis, a staggering $51 billion in crypto was lost to fraud in 2024 alone, with organized crime rings, state-sponsored hackers, and AI-driven scams leading the charge.
The FBI also reported a massive spike in losses, stating that Americans lost around $9.3 billion to crypto scams in 2024. Seniors over 60 were the most affected demographic.
Meanwhile, North Korean cybercriminals have stolen nearly $3 billion in crypto between 2017 and 2023—an operation that cybersecurity firm Paradigm says is becoming increasingly sophisticated.
Get the weekly commit
New blockchain deep dives every week.

