Water Kurita is a financially motivated cybercriminal group operating the Lumma Stealer infostealer-as-a-service for credential theft.
Analyst brief
Water Kurita is a financially motivated cybercriminal group known for operating the Lumma Stealer infostealer-as-a-service operation. It primarily targets large-scale credential and information theft, monetizing access through subscription-based malware distribution and the resale of stolen data to other actors. Key TTPs include infostealers, underground forum marketing, and exploitation of MaaS ecosystems, though a 2025 doxxing campaign significantly disrupted its activity. Defenders should focus on email protection and endpoint detection systems to block Lumma Stealer-associated download vectors, while also strengthening anomaly monitoring against potential use of stolen credentials.
Water Kurita
unknown
Water Kurita is a financially motivated cybercriminal entity associated with the Lumma Stealer infostealer-as-a-service operation, primarily active on underground forums and marketplaces. It focuses on credential and information theft at scale, monetizing access via subscription-based malware distribution and resale of stolen data to other actors. The group demonstrates solid operational security and marketing tactics typical of mature MaaS ecosystems, although a 2025 doxxing campaign exposing alleged core members (personal and financial data) significantly disrupted its activity and drove customers toward competing infostealers.
What is the primary method of operation for the Water Kurita group?+
Water Kurita is known for the Lumma Stealer infostealer-as-a-service operation, focusing primarily on large-scale credential and information theft through subscription-based malware distribution.
What disrupted the Water Kurita group's activity in 2025?+
A doxxing campaign in 2025 significantly disrupted Water Kurita's activity.