Also known as: Storm-2477, tracked as
Water Kurita is a financially driven cybercriminal collective that has been linked to the Lumma “Stealer” infostealer‑as‑a‑service (MaaS) ecosystem. The group rose to prominence after law‑enforcement takedowns of its central marketplace and command infrastructure, which exposed core members in a 2025 doxxing operation. Following these disruptions, Water Kurita quickly reestablished operations by deploying new C2 servers behind Cloudflare and expanding delivery via alternative channels. The actor’s delivery tactics pivot around GitHub-based fake or compromised repositories (the FakeGit campaign), as well as malvertising, search‑engine manipulation, and social‑media promotions on platforms such as YouTube and Facebook. These vectors funnel victims to an installer that leverages MicrosoftEdgeUpdate.exe for process injection into Chrome processes, enabling stealthy persistence and data gathering. On the technical side, Water Kurita relies heavily on browser fingerprinting and system profiling to evade sandbox detection. The malware performs dynamic exploitation of the IDRAC remote‑management firmware to wipe disks if remediation fails, and can employ a secondary payload (GhostSocks) for environment detection or lateral movement. Data exfiltration occurs over standard HTTP/HTTPS to C2 endpoints such as “/api/set_agent” on domains like jamelik.asia, using query‑parameterized GET requests that include user IDs and tokens. Operationally, Water Kurita sustains revenues by monetizing data in two phases: a subscription model that delivers freshly stolen credentials to customers, and an aftermarket resale of high‑value databases. Its persistence mechanisms enable rapid redeployment after takedowns, ensuring continued income streams despite counter‑measures.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Water Kurita is a financially motivated cybercriminal group that operates the Lumma Stealer MaaS platform, using stealthy browser deliveries and process injection to exfiltrate credentials on a mass‑scale. The group’s recent 2025 doxxing campaign exposed its core members and temporarily disrupted its infrastructure, but activity resumed quickly through new C2 channels and diversified delivery vectors. It primarily monetizes stolen data by reselling credentials via subscription services, targeting a wide array of sectors across China, Iran, Israel, and Japan.
Goals & Targeting
Water Kurita’s primary objective is financial gain through large‑scale credential theft and data monetization. The group specifically targets sectors that handle sensitive or highly profitable information, including media, financial services, pharmaceuticals, critical infrastructure, aviation, government, and defense. The actor focuses on threat landscapes in China, Iran, Israel, and Japan, exploiting localized supply chains and leveraging local regulatory gaps to maximize the value of stolen data.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Water Kurita operates at an opportune tempo, rapidly rebuilding its infrastructure after each takedown. Known campaigns include the high‑volume FakeGit GitHub repo abuse and a 2025 doxxing incident that forced operational pivots. Victim profiles span mid‑market organizations in finance, media, pharmaceuticals, critical infrastructure, aviation, government, and defense across China, Iran, Israel, and Japan. The actor’s modus operandi blends multiple delivery vectors—malvertising, social‑media, GitHub, and phishing—to maximize reach, while its use of cloud proxies and CDN masking enables resilient command & control despite defensive countermeasures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple publicly available reports, law‑enforcement takedown disclosures, and technical de‑composition of the Lumma Stealer malware. While there is high confidence in documented delivery methods, stealth techniques, and identified tools, gaps remain regarding the full organizational structure of Water Kurita, the exact operational tempo over time, and the detailed extent of its subscription/marketplace revenue model.
No campaigns linked yet.
No observed data linked yet.
19
Techniques
46
Tools
0
Campaigns
23
IOCs
0
Observed Data
9
Tactics