The Cybersecurity and Infrastructure Security Agency and the FBI have unveiled a joint cybersecurity advisory highlighting the serious threat posed by LummaC2 information stealer, or infostealer, malware.
Table of Contents
LummaC2 Malware Advisory
CISA said Wednesday the LummaC2 Malware Targeting U.S. Critical Infrastructure Sectors advisory outlines the tactics, techniques and procedures, or TTPs, as well as the indicators of compromise, known as IOCs, connected to threat actors using LummaC2 malware. The advanced malware presents a serious threat as it can infiltrate computer networks and exfiltrate sensitive data. This can target computer systems utilized by individuals and organizations across critical U.S. infrastructure.
Ongoing Malware Threat Activity
According to the FBI and third-party reports, this malware activity was observed as recently as May 2025. The IOCs detailed in this advisory are derived from LummaC2 malware infections from November 2023 through May 2025.
In light of these findings, CISA and the FBI are urging organizations to review the cybersecurity advisory and implement the recommendations found in the mitigations section.