LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1213: Lumma Stealer

MITRE ATT&CK S1213: Lumma Stealer Malware details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseS1213MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Lumma Stealer matters because ATT&CK identifies it as a Windows information-stealer malware family, in use since at least 2022, delivered as Malware-as-a-Service, with captured data sold in criminal markets to Initial Access Brokers. For leaders, the practical risk is not only the initial infected workstation; it is the downstream exposure of browser data, web session cookies, screenshots, staged files, and exfiltrated information that may enable later unauthorized access.

Executive priority

Prioritize Lumma Stealer as an identity and incident-response readiness issue, not just an endpoint malware issue. The ATT&CK relationships emphasize user-driven execution, browser/session theft, local collection, C2 over web protocols, and exfiltration. Executives should ask whether the organization can rapidly identify affected Windows hosts, determine what browser/session data may have been exposed, invalidate relevant sessions, preserve evidence, and show auditors that endpoint, network, and identity response controls are operating.

Technical view

ATT&CK does not provide official detection text for S1213, so validation should be relationship-driven. On Windows, test whether SOC coverage can connect suspicious user execution or malicious files with PowerShell, Python, AutoHotKey/AutoIT, mshta, Electron abuse, process hollowing, obfuscated or encoded payloads, deobfuscation activity, browser information discovery, browser extension abuse, local data staging, screen capture, web-protocol C2, and exfiltration over that channel. IR playbooks should include host triage, browser artifact review, session-cookie risk assessment, network destination review, and identity containment decisions.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • PowerShell and script interpreter activity, including Python, AutoHotKey, and AutoIT where present
  • File creation, file type mismatch, encoded/encrypted content, and local staging directories
  • EDR memory/process behavior relevant to process hollowing
  • mshta.exe and Electron application execution context

Detection direction

  • Do not rely on a single malware signature; the supplied ATT&CK coverage points to behavior spanning execution, stealth, discovery, collection, credential access, C2, and exfiltration.
  • Tune detections for suspicious combinations: user-opened files followed by script execution, obfuscated payload handling, browser data access, local staging, and outbound web traffic to unusual destinations.
  • Review false positives carefully for administrative scripting, legitimate automation tools, Electron-based business applications, and normal browser extension activity.
  • Validate visibility gaps around encrypted web traffic, unmanaged Windows endpoints, personal browser profiles, and endpoints where PowerShell or script logging is incomplete.
  • Correlate endpoint alerts with identity actions because stolen session cookies may bypass normal password-focused response assumptions.

Mitigation priorities

  • Harden initial execution paths: restrict or monitor risky file execution, script interpreters, mshta, and unauthorized automation tools on Windows.
  • Reduce browser-derived exposure by governing extensions, limiting unmanaged browser use for business access, and ensuring session revocation procedures are available during IR.
  • Improve endpoint and network telemetry retention so responders can reconstruct local collection, staging, and outbound web communications.
  • Prepare identity containment steps for suspected cookie or browser data theft, including session invalidation and review of authenticated web activity.
  • Use user-awareness and software-source controls to reduce execution of deceptive or untrusted files, consistent with the ATT&CK relationships for user execution and supply-chain style delivery mechanisms.
Additional notes and limits

The strongest decision value is in treating S1213 as a credential/session and data-exfiltration scenario. ATT&CK lists Windows as the platform for the malware object and provides many behavior relationships, but no object-level tactics or official detection guidance. Defensive validation should therefore be based on the related techniques and local evidence.

This take is limited to the supplied ATT&CK STIX fields, external references, and relationships. It does not assert current targeting, attribution, customer exposure, or guaranteed detection. Local environment baselines, tool capabilities, legal constraints around browser artifact collection, and available log retention will determine practical coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Lumma Stealer

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
c98be942b2f1f6e2...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.