All things infostealers. Week 7, 2025


A brief look at all things infostealers for the week 7, 2025 (10.02.2025–16.02.2025). This week observed updates from LummaC2 infostealer. Grabbed some numbers from marketplaces and have some interesting reports/articles about stealers.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English)

Update 16.02

  1. Session security has been improved
  2. Improved performance and meaningfulness of metrics
  3. Improved file security
  4. Authorization security is improved
  5. Cleaning WD 10/11 + Cloud + Run-Time

Screenshot from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Now this is intriguing. There’s a new stealer name “Acreed”, never heard of it and a quick search didn’t result in anything meaningful.

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,363,035
RisePro1,430,063
Vidar1,293,386
StealC1,005,561
RedLine790,305
Raccoon330,549
Acreed1,279
Top 5 countries by number of victims
CountryNumber of victims
India1,217,385
Brazil971,586
Indonesia663,920
Egypt617,471
Pakistan599,011
Nordic region countries
CountryNumber of victims
Sweden19,761
Denmark10,605
Norway8,165
Finland7,007
Iceland1,023
Faroe94
Åland16

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
RedLine133,326
Lumma94,248
Vidar56
Unknown10
Top 5 countries by number of victims
CountryNumber of victims
Peru7,306
Turkey7,177
India6,309
Pakistan6,285
Vietnam5,822
Nordic region countries
CountryNumber of victims
Norway144
Sweden96
Denmark47
Finland44
Iceland10

Articles/News

DeepSeek ClickFix Scam Exposed! Protect Your Data Before It’s Too Late

  • https://www.cloudsek.com/blog/deepseek-clickfix-scam-exposed-protect-your-data-before-its-too-late

OpenAI Finds No Evidence of Breach After Hacker Offers to Sell 20 Million Credentials

  • https://www.securityweek.com/openai-finds-no-evidence-of-breach-after-hacker-offers-to-sell-20m-credentials/

PirateFi game on Steam caught installing password-stealing malware

  • https://www.bleepingcomputer.com/news/security/piratefi-game-on-steam-caught-installing-password-stealing-malware/