All things infostealers. Week 12, 2025


A brief look at all things infostealers for the week 12, 2025 (17.03.2025–23.03.2025). This week observed updates from LummaC2 infostealer. Grabbed some numbers from marketplaces and have some interesting reports/articles about stealers.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Update 18.03

  1. Fixed LevelDB collection for extensions that require it (e.g. Coinbase).
  2. Fixed MetaMask collection in Mozilla browsers
  3. Fixed launching of large PowerShell scripts when “From memory” launch type is selected
  4. Fixed knockback through spare gaskets
  5. Cleaned WD 10/11 + Cloud + Run-Time

Screenshot taken from user’s post on XSS forum

Update 20.03

  1. Returned LID to System.txt
  2. Fixed and improved cookie collection
  3. Fixed a bug that could cause builds with a long tag not to work
  4. Cleaned up WD 10/11 + Cloud + Run-Time

Screenshot taken from user’s post on XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma8,057,305
RisePro1,429,672
Vidar1,293,990
StealC1,005,337
RedLine789,992
Raccoon330,144
Acreed14,621
Top 5 countries by number of victims
CountryNumber of victims
India1,311,314
Brazil1,020,297
Indonesia702,923
Egypt643,414
Pakistan632,075
Nordic region countries
CountryNumber of victims
Sweden21,199
Denmark11,357
Norway8,866
Finland7,485
Iceland1,100
Faroe104
Åland18

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
RedLine166,092
Lumma114,793
Vidar56
Unknown10
Top 5 countries by number of victims
CountryNumber of victims
Peru7,306
Turkey7,176
India6,307
Pakistan6,285
Vietnam5,822
Nordic region countries
CountryNumber of victims
Norway143
Sweden96
Denmark47
Finland44
Iceland10

Articles/News

Infostealers fueled cyberattacks and snagged 2.1B credentials last year

  • https://cyberscoop.com/infostealers-cybercrime-surged-2024-flashpoint/

Arcane stealer: We want all your data

  • https://securelist.com/arcane-stealer/115919/

Rilide – An Information Stealing Browser Extension

  • https://blog.pulsedive.com/rilide-an-information-stealing-browser-extension/

Steam pulls game demo infecting Windows with info-stealing malware

  • https://www.bleepingcomputer.com/news/security/steam-pulls-game-demo-infecting-windows-with-info-stealing-malware/