All things infostealers. Week 10, 2025


A brief look at all things infostealers for the week 10, 2025 (03.03.2025–09.03.2025). This week observed updates from LummaC2 infostealer. Grabbed some numbers from marketplaces and have some interesting reports/articles about stealers.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English)

Update 6.03

  1. Completely changed communication protocol between build and server
  2. Added packet encryption
  3. Added “in-the-moment” gasket rotation if the previous gasket became unavailable
  4. Added resend data if previous send failed
  5. Improved traversal for gaskets with warp from cloud
  6. Clean WD 10/11 + Cloud

Screenshot from XSS Forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,795,027
RisePro1,429,817
Vidar1,292,996
StealC1,005,269
RedLine790,106
Raccoon330,308
Acreed9,750
Top 5 countries by number of victims
CountryNumber of victims
India1,274,542
Brazil1,001,728
Indonesia688,806
Egypt633,848
Pakistan618,074
Nordic region countries
CountryNumber of victims
Sweden20,694
Denmark11,153
Norway8,615
Finland7,314
Iceland1,069
Faroe101
Åland16

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
RedLine116,315
Lumma101,859
Vidar56
Unknown10
Top 5 countries by number of victims
CountryNumber of victims
Peru7,306
Turkey7,176
India6,307
Pakistan6,285
Vietnam5,822
Nordic region countries
CountryNumber of victims
Norway143
Sweden96
Denmark47
Finland44
Iceland10

Articles/News

Exposing Russian EFF Impersonators: The Inside Story on Stealc & Pyramid C2

  • https://hunt.io/blog/russian-speaking-actors-impersonate-etf-distribute-stealc-pyramid-c2

Prospering Lumma

  • https://intelinsights.substack.com/p/prospering-lumma

Malvertising campaign leads to info stealers hosted on GitHub

  • https://www.microsoft.com/en-us/security/blog/2025/03/06/malvertising-campaign-leads-to-info-stealers-hosted-on-github/

Kaspersky: stealer malware leaked over 2 million bank cards

  • https://www.kaspersky.com/about/press-releases/kaspersky-stealer-malware-leaked-over-2-million-bank-cards

A Deep Dive into Strela Stealer and how it Targets European Countries

  • https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/a-deep-dive-into-strela-stealer-and-how-it-targets-european-countries/