Trend Micro’s latest research has revealed a resurgence in Lumma Stealer activity, tracked internally as Water Kurita, following a temporary downturn after its developers were doxxed in October.
Despite the brief disruption during which many users migrated to alternatives such as Vidar and StealC, the infostealer has resurfaced with new command-and-control (C&C) strategies that integrate advanced browser fingerprinting techniques.
Telemetry data from Trend Vision One™ showed a significant spike in Lumma activity starting the week of October 20, 2025.
These new samples leverage fingerprinting to collect detailed system, network, and browser-level information using JavaScript payloads and stealthy HTTP communications, signaling a pivot toward improved detection evasion and environment profiling.
Fingerprinting-Based Command-and-Control Mechanism
Lumma Stealer’s latest version introduces a dedicated C&C endpoint /api/set_agent designed to handle browser fingerprinting operations. Initial HTTP GET requests to this endpoint include parameters such as a 32-character device identifier (id), a session token, and the browser agent.
The malware then transmits system and browser details, including user-agent strings, CPU cores, GPU renderer data (via WebGL), and audio device characteristics.
Collected data is serialized into JSON and exfiltrated through an HTTP POST request to the same endpoint, using act=log. The fingerprinting script subsequently redirects the browser to about:blank, minimize the likelihood of detection by the user.

This module supplements Lumma Stealer’s traditional WinHTTP-based C&C routine, which continues to exfiltrate campaign and client identifiers (uid and cid). The integration suggests an additive approach, augmenting proven infrastructures rather than replacing them.
Stealth, Resilience, and Tactical Goals
Trend’s analysis of infected hosts revealed that Lumma Stealer employs process injection techniques, such as injecting a remote thread from MicrosoftEdgeUpdate.exe into chrome.exe, enabling execution within legitimate browser contexts.
This method obfuscates malicious activity under trusted processes, complicating network-based detection.
The enhanced fingerprinting capability serves multiple purposes: identifying sandbox environments, tailoring payloads based on system profiles, and sustaining operational continuity amid increasing scrutiny.
Despite degraded operational security, such as outdated C&C domains and reduced underground visibility, Water Kurita remains an active and adaptive threat actor.
Trend Vision One™ customers are advised to hunt for suspicious activities, including events referencing /api/set_agent, .mid or .mid.bat file movements, and remote thread injection behaviors.
Implementing software installation controls, enhanced phishing awareness, and multi-factor authentication can further reduce exposure to Lumma Stealer’s evolving threats.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates