# Water Kurita

> As of 2026-08-04, Water Kurita is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as Storm-2477, Lumma Stealer operators, LummaC2 affiliates. ATT&CK coverage spans 53 techniques across 11 tactics in 3 of 3 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1140 (Deobfuscate/Decode Files or Information), T1539 (Steal Web Session Cookie).

- **Tracked threats:** 3
- **Categories:** MALWARE
- **Also known as:** Storm-2477, Lumma Stealer operators, LummaC2 affiliates
- **As of:** 2026-08-04

## ATT&CK techniques observed

53 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (12), Execution (8), Command and Control (7), Credential Access (5), Discovery (5), Initial Access (4).

- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 3 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 3 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 3 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 3 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 3 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 3 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 2 of 3 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 2 of 3 tracked threats
- [T1547](https://intel.threadlinqs.com/technique/T1547) Boot or Logon Autostart Execution — Persistence — observed in 2 of 3 tracked threats
- [T1555](https://intel.threadlinqs.com/technique/T1555) Credentials from Password Stores — Credential Access — observed in 2 of 3 tracked threats
- [T1564](https://intel.threadlinqs.com/technique/T1564) Hide Artifacts — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats

## Tracked threats

- [TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Repos](https://intel.threadlinqs.com/threat/TL-2026-1859) — HIGH
- [FakeGit Campaign: 7,600 Malicious GitHub Repos Push SmartLoader and StealC Malware via AI Tool Poisoning (Water Kurita)](https://intel.threadlinqs.com/threat/TL-2026-1595) — HIGH
- [Fake GitHub 'EQVita' Homebrew Repo Delivers SmartLoader and Lumma Stealer to the Retro Gaming / PlayStation Vita Modding Community](https://intel.threadlinqs.com/threat/TL-2026-0849) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Water%20Kurita
