All things infostealers. Week 3, 2025


A brief look at all things infostealers for the week 3, 2025 (13.01.2025–19.01.2025). This week observed updates in LummaC2 and Xerph infostealers. Grabbed some numbers from marketplaces and have some interesting reports about stealers.

Infostealer Updates

Xerph

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English)

Xerph 1.1.6 Loader + Stealer (Update)
Changes:
IP blacklisting has been added

Screenshot from XSS forum

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English)

Update 11.01

  1. Cleaning WD 10/11 + Cloud
  2. Cleaning LNK builder

Screenshot from XSS forum

Update 15.01

  1. Improved search by url
  2. Improved password search + fixed .txt loading
  3. Improved password filter handling
  4. Added ability to output different number of logs per page
  5. Added method to get all logs via API
  6. Common gaskets replaced
  7. Cleaning WD 10/11 + Cloud

Screenshot from XSS forum

Update 18.01

  1. Cleaned up WD 10/11 + Cloud
  2. Changed gasket encryption method

Screenshot from XSS forum

Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims

StealC have reached 1 million infections!

Stealer nameNumber of victims
Lumma6,462,235
RisePro1,430,357
Vidar1,292,951
StealC1,000,415
RedLine790,630
Raccoon330,930
Top 5 countries by number of victims
CountryNumber of victims
India1,097,525
Brazil908,871
Indonesia604,540
Egypt578,718
Pakistan558,112
Nordic region countries
CountryNumber of victims
Sweden18,009
Denmark9,584
Norway7,401
Finland6,434
Iceland918
Faroe84
Åland15

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
RedLine87,995
Lumma54,959
Vidar56
Unknown10
Top 5 countries by number of victims
CountryNumber of victims
Peru7,305
Turkey7,179
India6,307
Pakistan6,284
Vietnam5,823
Nordic region countries
CountryNumber of victims
Norway144
Sweden96
Denmark47
Finland44
Iceland10

Articles/News

What is this Stealer

  • https://github.com/MalBeacon/what-is-this-stealer

Infostealer Infections Lead to Telefonica Ticketing System Breach

  • https://www.securityweek.com/infostealer-infections-lead-to-telefonica-internal-ticketing-system-breach/

How Cracks and Installers Bring Malware to Your Device

  • https://www.trendmicro.com/en_us/research/25/a/how-cracks-and-installers-bring-malware-to-your-device.html

MintsLoader: StealC and BOINC Delivery

  • https://www.esentire.com/blog/mintsloader-stealc-and-boinc-delivery

Hunting Infostealers: A Practical Approach

  • https://www.gov.il/BlobFolder/reports/alert_1848/he/ALERT-CERT-IL-W-1848.pdf