All things infostealers. Week 11, 2025


A brief look at all things infostealers for the week 11, 2025 (10.03.2025–16.03.2025). This week observed updates from LummaC2, Xerph, Prysmax infostealers and emergence of a stealer targeting macOS. Grabbed some numbers from marketplaces and have some interesting reports/articles about infostealers.

If you have questions/suggestions/feedback/whatever feel free to contact me.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Update 11.03

  1. Fixed a bug where uploading from the password search page could be incomplete
  2. Fixed collection on Windows 7
  3. Cleaned WD 10/11 + Cloud

Screenshot taken from user’s post on XSS forum


Xerph

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Xerph 1.1.8 Loader + Stealer (Update)

Changes:
Resolved crashes in the browser recoverer (Passwords and CCs)
Added +3 recoverable wallets:
Franko
Freicoin
Yacoin

Screenshot taken from user’s post on XSS forum


Prysmax

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Prysmax v1.0.8

  • Now the password shortener is much more efficient and faster
    It also shows how many results it found, how many processes are running, and you can export your search as ULP or in general.
  • The country chart has been replaced with a world map chart.
  • A new feature has been added to the Builder: “Pumper”
    You can now add weight to the file to your own liking.
  • The Discord sorter has been updated
    Now it only allows exporting tokens for 24 hours, 7 days, and historical data.

Screenshot taken from Prysmax’s Telegram channel


mac.c

Refer to my earlier post: mac.c macOS Stealer


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,986,936
RisePro1,429,732
Vidar1,293,736
StealC1,005,195
RedLine790,044
Raccoon330,191
Acreed14,011
Top 5 countries by number of victims
CountryNumber of victims
India1,300,845
Brazil1,015,624
Indonesia699,396
Egypt640,509
Pakistan627,604
Nordic region countries
CountryNumber of victims
Sweden21,020
Denmark11,293
Norway8,787
Finland7,426
Iceland1,089
Faroe104
Åland17

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
RedLine142,243
Lumma111,336
Vidar56
Unknown10
Top 5 countries by number of victims
CountryNumber of victims
Peru7,306
Turkey7,176
India6,307
Pakistan6,285
Vietnam5,822
Nordic region countries
CountryNumber of victims
Norway143
Sweden96
Denmark47
Finland44
Iceland10

Articles/News

AI-Assisted Fake GitHub Repositories Fuel SmartLoader and LummaStealer Distribution

  • https://www.trendmicro.com/en_us/research/25/c/ai-assisted-fake-github-repositories.html