All things infostealers. Week 6, 2025


A brief look at all things infostealers for the week 6, 2025 (03.02.2025–09.02.2025). This week observed updates from LummaC2 infostealer. Grabbed some numbers from marketplaces and have some interesting reports/articles about stealers.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English)

Update 6.02

  1. Improved parsing of installed antiviruses
  2. Improved the behavior of the knocking statistics, now the target values are adjusted automatically
  3. Increased security of sessions in the panel
  4. Fixed a bug in the build when System.txt might not always arrive
  5. Cleaning WD 10/11 + Cloud

Screenshot from XSS forum

Update 9.02
Added “improved proxies”. This means that if the proxy is banned, you can replace it at any time and keep the knock.

Screenshot from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,172,570
RisePro1,430,151
Vidar1,293,553
StealC1,005,663
RedLine790,409
Raccoon330,650
Top 5 countries by number of victims
CountryNumber of victims
India1,194,543
Brazil959,400
Indonesia651,175
Egypt609,583
Pakistan591,595
Nordic region countries
CountryNumber of victims
Sweden19,331
Denmark10,408
Norway7,987
Finland6,867
Iceland999
Faroe93
Åland15

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
RedLine119,438
Lumma80,313
Vidar56
Unknown10
Top 5 countries by number of victims
CountryNumber of victims
Peru7,306
Turkey7,178
India6,309
Pakistan6,285
Vietnam5,822
Nordic region countries
CountryNumber of victims
Norway144
Sweden96
Denmark47
Finland44
Iceland10

Articles/News

Stealers on the Rise: A Closer Look at a Growing macOS Threat

  • https://unit42.paloaltonetworks.com/macos-stealers-growing/

Kimsuky APT group used custom RDP Wrapper version and forceCopy stealer

  • https://securityaffairs.com/173991/apt/north-koreas-kimsuky-forcecopy-malware.html