LummaC2 - universal stealer, a malware for professionals.

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
LummaC2 is a new generation stealer, average knock 75-85%, works even on clean systems, no dependencies (AT ALL), log decryption on the server, build weight 150-300KB, steals Chromium and Mozilla based browsers, steals ~70 browser cryptocurrency and 2FA extensions, has a new method of bypassing Google unlogins (validity reaches 90-95%), non-resident Loader, low-level adaptive filegrabber, AI to detect bots in the panel, and the latest unique development - BINARY MORPHER.

LummaC2 is updated literally every two hours, add your specific browser or your specific extension - 2 clicks!

Technical information:​

  • The language used in the development of this product is C
  • Virtually no high-level WINAPI is used
  • The product is on the most powerful servers with anti-DDoS protection.
  • All decryption is completely server-based, all data transmitted by the stealer is decrypted on the server.
  • In order to increase chunking, data is sent in chunks.
  • The weight of the build is 150-300KB, CRT is present but not used, on request if you care about weight, link CRT from another studio, the weight will decrease in the process, UPX will compress the build to 80KB, but it is not recommended to do this procedure
  • A neighbor detection system is available, as well as a traffic quality monitoring system
  • System calls support ARM, x86, x64 architectures
  • Stealer works on operating system versions from Windows 7 x32 to Windows 11 x64 with the latest updates.
  • There is a knock in Telegram bot / channel, both about the arrival of the log, and the log itself
  • All interaction with the OS is done through calls to a low-level wrapper written in ASM over system calls, no WinAPI only manual syscall calls (corporate rate).
  • Where WinAPI is used - its calls are encrypted (read custom GetProcAddress)
  • Implemented Heavens Gate technology allowing to switch from WoW64 mode (corporate tariff)
  • Spreading without crypt protection
  • DomainDetect is included in the log format
  • Build is covered by default by our binary morpher with Control flow.
  • Non-residential Loader
  • Google unlogins bypass implemented (90-95% validity)
  • CC collection is implemented
  • Gasket rotation is implemented, 1+10 addresses are sewn into the build (instead of 1+1 main and backup addresses before), it increases survivability and stability of the build many times.
Screenshot of panel (Clickable)
Log format:
1d5a9f473ceb4413cec6f.jpg



Pricing plans:

EXPERIENCED

  • Set filters up to 10 .
  • Download logs in bulk
  • Possibility to upload logs by your search query (for example - only with wallets or only with instagram.com)
  • Ability to use search by parameters (country, with or without currency, with a specific filter)
  • Ability to clear dumps, dumps statistics on the "quality of logs" page
  • 3 tags for builds
PRICE: $250/month
--------
PROFESSIONAL

  • All features of previous privileges
  • Unlimited number of filters
  • Logs can be deleted in bulk (by zeroing the counter)
  • Share your stats with others
  • Logs quality widget available
  • Filter widget is available
  • Search widened, logs search and downloading is available by request (in cookies/passwords)
  • Ability to monitor number of neighbors in logs
  • Logs quality rating system available
  • Ability to create and edit grabber profiles
  • Ability to add and remove extensions
  • Ability to add and remove browsers
  • Ability to add and remove paths for looting
  • Ability to use masks as well as variable paths
  • Ability to edit the data to be collected and the order of data collection, e.g. someone needs to collect cid phrases first and someone needs to collect chrome first
  • Ability to customize the depth of data collection
  • Ability to always roll back to default settings
  • Ability to create an unlimited number of rules in the profile
  • Ability to edit profile "hot", to change data collected by the stealer right during spreading
  • Non-residential Loader
PRICE: $500/month
--------
CORPORATE

  • Previous privileges features
  • Dedicated build cleanup line, build is cleaned more often
  • Improved bypass of proactive protection (no message LummaC2.exe tries to access password store), build lives longer
  • Google Unlogging Bypass (90-95% validity)
  • Great for you-know-where point-level security breaches
  • Generation of random builds by our morpher, each build is individual, different from the other
PRICE: $1.000/month

FAQ​

Question: What happens after my subscription ends?
Answer: If your subscription ends, your traffic will not go anywhere, after the resumption of the subscription, logs during your inactivity will be waiting for you in the panel, this applies to ALL tariff plans.

Question: What guarantee on bounce rate?
Answer: It is impossible to say for sure at any particular moment, it depends on crypto and on how much time has passed after cleaning. In average on different exchanges and different crypto is 75%-85%.

Question: If I bought some tariff and its price increased during the process, will I pay this difference in price?
Answer: The clients, who bought the tariff the price is not indexed, the prices are indexed only for the new clients.

Question: How often does the cleaning take place?
Answer: We try to clean the build as often as possible. All tariffs except corporate are cleaned every 5 days. Corporate rate is cleaned every 2 days.

Question: Is crypt required?
Answer: Yes, crypt is required. The build is native, it is easy to crypt - there are partners who will make you a crypt without any problems.

Question: Does the stealer knock in CIS?
Answer: No and will not knock. Do not offer us any money - in any case there will be a refusal.

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 
Last edited:
  • Like
Reactions: X

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
photo_2023-07-12_00-00-43.jpg
Update 12.07
One of the biggest updates that we have been preparing for a long time, it is now possible to customize EVERYTHING that builds stealer! The ability to add your own extensions, your own paths, the ability to create configurations (hereinafter profiles), and when downloading a build to assign it a specific profile and edit the rules right during the shedding! This grabber is the most flexible on the market.
ATTENTION! The functionality is available starting from the tariff [Professional].
1. Ability to create and edit grabber profiles
2. Ability to add and remove extensions
3. Ability to add and remove browsers
4. Ability to add and remove paths for looting
5. Ability to use masks as well as variable paths
6. Ability to edit the data to be collected and the order of data collection, e.g. someone needs to collect cid phrases first and someone needs to collect chrome first
7. Ability to customize the depth of data collection
8. Ability to always roll back to default settings
9. Ability to create an unlimited number of rules in the profile
10. Ability to edit profile "hot", to change data collected by the stealer right during spreading
11. On the download page it is now possible to select the profile with which the build will work.
12. Builds are cleaned.


• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
Update 19.07
1. There is now a Loader inside the stealer that can load files to the victim machine at any stage of program execution
2. Ability to load EXE files
3. Ability to load DLL files
4. Ability to load PowerShell files
5. The ability to disable screenshot collection has appeared
6. Ability to enable self-deletion after workback
7. Improved fault tolerance, when custom pads are unavailable, styler switches to one of the main pads
8. Now the really important innovation.... The "Grabber" tab has been renamed to the "Config" tab, it makes more sense now
9. Added several new fields to System.txt, in particular - domain group
XBmB6wK.jpg


• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
Update 21.07
31Sa2WQ.jpg

1. On the logs page it is now possible to search by application
2.Time interval is now more convenient to select (time interval mask coincides with the mask of log arrival time).
3. The time interval now works on an "inclusive" basis
4. It is now possible to scroll through all pages at once on the logs page (the END button).
5. The work of the panel has been optimized

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
1690415053319.png


Update 27.07
One of the updates that seems insignificant from the client side, but gives a very big step forward to those who work with malware and stealers in particular. It's no secret that the main problem with stealers is that the build starts to die immediately after cleaning and gradually the knock of the once crystal clear build comes to naught, but even worse - you have to wait until the cleaning is done. We fix this problem. Now when you click on the button to download a build you will always... A randomly generated build thanks to our morpher. And yes, this is not the source morpher which is optimized during compilation, this is not cheap knockoffs of competitors, this is a personal development on which we spend a lot of time and money, this is a product of a different quality, which allows you to make completely different builds every compilation (they even have different weights), so do not confuse this development with Garble (obfuscator for Golang, hello to all stealers on Go), and now this beast is available in senior rates.

1. Now when downloading a build in the panel you will always get a randomly generated build.
2. A general cleanup has been done for all tariffs.

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
Thinking about buying a subscription to LummaC2? Especially for you we have made an actual full review with description and advantages of our product over competitors. Hundreds of satisfied customers, impeccable market reputation and the latest unique developments - choose the best service.
Full description of LummaC2 (CLICK)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
Update 31.07
1. Cleaned up
2. Fixed problem with non-unique HWID, which could cause logs to be split
3. Improved fault tolerance, critical server processes are now automatically restarted in case of crashes and any other mishaps, and traffic is routed to the backup server
4. Disabled IPv6 on the main pavement now all IPv6 (where possible) are automatically translated to IPv4.

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
photo_2023-08-02_00-13-13.jpg


Update 2.08
1. Filters can now be added comma-separated, in hundreds and dozens at once
2. Due to the increased functionality, menu items are now named more logically
3. On the page of logs according to the tariff there is now a button "Remove empty items". 3.
4. The button to delete all logs is now painted in bright red color, so that in addition to warnings that it will demolish irrevocably all logs was also color indication for those who can not read and oriented on color
5. Fixed an error with the detection of neighbors when normal logs on the meter could go into the minus.

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
92eKFJu.jpg

Update 5.08
1. Cleaned up
2. Now it is possible to specify masks separated by commas in the filegrabber settings.
3. You can now specify a limit on the size of the collected file in the file grabber settings
4. New extensions added to the standard config: Rabby, Pontem, Martian, Bitwarden, Nami, Petra, Sui, ExodusWeb3, Binance Wallet, Sub, PolkadotJS, Talisman, MEWCX, EnKrypt, CryptoCom
5. New email clients added: TheBat, Pegasus Mail, Mailbird, EmClient
6. Added new masks to the grabber


• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
Update 10.08
1. Build tags are now available in the [Experienced] plan, it is possible to set up to three tags, including the standard build tag.
2. Plans above [Experienced] can create as many build tags as they like
3. Fixed a bug with forbidden characters in build tags.
4. Cleaned up

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
photo_2023-08-17_00-23-05.jpg


Update 17.08
Creating gasket is now more logical. No need to enter your telegram. You write to the support - he gives you a gasket, you activate it when you need it.
1. Changed the logic of issuing gaskets
2. Removed the premoderation of gaskets
3. Gaskets are now ordered faster
4. Redesigned gasket page


• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
Update 18.08
1. The "share stats" page has been transformed, now works great on mobile devices as well
2. On the "share stats" page, when hovering over a country on the map, you can now see how many logs came from a specific country
3. the general padding has been replaced, it is now cleaner

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
Update 18.08
1. The "share stats" page has been transformed, now works great on mobile devices as well
2. On the "share stats" page, when hovering over a country on the map, you can now see how many logs came from a specific country
3. the general padding has been replaced, it is now cleaner

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
photo_2023-08-21_00-52-02.jpg
Update 21.08.
1. The filters functionality has been updated, now you can specify as many filters as you want and combine them into tags
2. The filters page has been completely redesigned
3. Made it possible to select the color and tag of a new filter
4. Redesigned filter search, now you can search not by a specific URL, but immediately by tag
5. It is now possible to delete logs by search query, for example, for a certain period of time, or only with wallets, or delete only downloaded ones
6. The page "My logs" began to behave more logically, for example, the button "unload all logs" or "unload logs by search query" is removed if there are no logs in fact.

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
photo_2023-08-23_17-20-13.jpg

photo_2023-08-23_17-24-18.jpg


Update 23.08.
Added functionality for vorkers/workers. Now if you want to share only FB logs for example, you just need to do a few simple actions: Go to "My Logs" > Search by filter (facebook) > Click the share logs button > Give the link to the developer. You don't need to do anything else. The developer will receive the latest actual logs without your participation and it is not necessary to give him login details to the panel. When you stop cooperating with the developer, delete the link and the developer will no longer be able to see your logs. Thus you can choose any combination of filters and create links to these combinations, for example: only without wallets, only with YouTube and only for today. The key point is that you do not need to give your login details to the panel to the developers and then think about where the logs are leaking out

1. Added "Workers" tab
2. now you can share certain logs by filters, like filters in search.
3. When you apply a search, a "Share logs" button appears
4. You can share a link, but prevent logs from being downloaded
5. Viewing statistics is available for the created links
6. All the latest innovations, such as detection of bots using AI, are available on the page on the link with logs
7. Now you don't need to give your panel data to the developers.


• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
Autumn is approaching, it's time to get back to work.
Be sure to get your LummaC2 subscription at a discounted rate from 24.08 to 31.08.

Experienced
250$ 225$
Professional
500$ 450$
Corporate
1000$ 900$

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)
 

LummaStealer

Seller
Joined
10 Jul 2023
Messages
112
Reaction score
2
Points
18
Telegram
photo_2023-08-31_16-26-13.jpg


Update 31.08.
1. Cleaned up
2. fixed frequent unlogins from google services
3. Large optimization of widgets, rewritten rendering, revised logic of counters and graphs.
4. Large optimization of the panel, now it loads almost 40% faster
5. Bulk upload of logs by guest links is now available
6. Alerts have been updated in the panel, now they are more modern.

• Contacts(RU/EN):
Support/Seller - @lummaseller126
Telegram Channel (Clickable)