Lumma Stealer has been the subject of two disruption operations and is reported to be running on around 394,000 machines. We are filing it alongside this quarter’s enforcement successes deliberately.
Coverage of takedowns is structurally optimistic. The announcement is a discrete event with impressive numbers and an obvious narrative. The recovery is gradual, unannounced, and reported by nobody.
What Actually Gets Destroyed
A disruption typically removes command infrastructure and domains. What it does not remove is the code, the operators, the affiliate relationships, the customer base or the revenue model.
For a commercial stealer sold as a service, those intangibles are the business. Infrastructure is an operating cost, and the disruption reads to the operator as an outage rather than an ending.
This Is Not An Argument Against Enforcement
Disruption imposes cost, produces intelligence, and — as in the Endgame phase filed in 26-0624 — recovers credentials that directly help victims. Those are real results.
The argument is against a specific inference: that a family named in a takedown announcement is now a solved problem and can be dropped from a detection roadmap. An organisation that removed Lumma coverage after the first operation has spent the period since undefended against something running on nearly 400,000 machines.
Graded medium. The installed-base figure comes from a single analysis and we have not seen it independently reproduced.
Compiled from published reporting, listed below. The 394,000 figure is as reported by a single source and is not independently corroborated. Corrections: corrections@forensicpost.com.