All things infostealers. Week 8, 2025


A brief look at all things infostealers for the week 8, 2025 (17.02.2025–23.02.2025). This week observed updates from the LummaC2 infostealer. Grabbed some numbers from marketplaces and have some interesting reports/articles about stealers.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English)

Update 17.02

  1. Added automatic leak prevention algorithms
  2. Added algorithms to counteract fraud from workers
  3. Added ability to freeze accounts if suspicious activity is detected
  4. Added ability to change password and unlog sessions as soon as possible
  5. Implemented a set of security measures
  6. Cleaning of LNK-builder

Screenshot from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,518,426
RisePro1,429,984
Vidar1,293,265
StealC1,005,451
RedLine790,228
Raccoon330,477
Acreed4,317
Top 5 countries by number of victims
CountryNumber of victims
India1,238,071
Brazil981,798
Indonesia673,467
Egypt624,302
Pakistan605,340
Nordic region countries
CountryNumber of victims
Sweden20,074
Denmark10,740
Norway8,286
Finland7,087
Iceland1,039
Faroe97
Åland16

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma91,896
RedLine100,515
Vidar56
Unknown10
Top 5 countries by number of victims
CountryNumber of victims
Peru7,306
Turkey7,177
India6,308
Pakistan6,285
Vietnam5,822
Nordic region countries
CountryNumber of victims
Norway143
Sweden96
Denmark47
Finland44
Iceland10

Articles/News

Lumma Stealer Chronicles: PDF-themed Campaign Using Compromised Educational Institutions’ Infrastructure

  • https://www.cloudsek.com/blog/lumma-stealer-chronicles-pdf-themed-campaign-using-compromised-educational-institutions-infrastructure

An Update on Fake Updates: Two New Actors, and New Mac Malware (FrigidStealer)

  • https://www.proofpoint.com/us/blog/threat-insight/update-fake-updates-two-new-actors-and-new-mac-malware

ACRStealer Infostealer Exploiting Google Docs as C2

  • https://asec.ahnlab.com/en/86390/

Rhadamanthys Infostealer Being Distributed Through MSC Extension

  • https://asec.ahnlab.com/en/86391/

LummaC2 Malware Distributed Disguised as Total Commander Crack

  • https://asec.ahnlab.com/en/86435/

Lumma Stealer Malware Thrives as Silent Push Uncovers Unique Patterns in the Infostealer’s Domain Clusters

  • https://www.silentpush.com/blog/lumma-stealer/