All things infostealers. Week 13, 2025


A brief look at all things infostealers for the week 13, 2025 (24.03.2025–30.03.2025). This week observed updates from LummaC2 and StealC infostealers. Grabbed some numbers from marketplaces and have some interesting reports/articles about stealers.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

**Update 28.03 **

  1. Added computer, hostname, bios keys for knocking in Telegram
  2. Added the ability to specify filters from a new line
  3. Fixed problem with automatic blank line in the message input field for knocking in Telegram
  4. Fixed decryption of cookies, tokens and passwords when collected from administrator

Screenshot from XSS Forum

Update 29.03

  1. Cleaning WD 10/11 + Cloud + Run-Time
  2. Cleaning lnk-builder

Screenshot from XSS Forum


StealC

Since there’s a major update to StealC, I decided to make a separate blog post about it.


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma8,195,121
RisePro1,429,610
Vidar1,297,376
StealC1,005,896
RedLine789,927
Raccoon330,085
Acreed17,117
Top 5 countries by number of victims
CountryNumber of victims
India1,331,647
Brazil1,029,244
Indonesia710,173
Egypt649,241
Pakistan640,289
Nordic region countries
CountryNumber of victims
Sweden21,470
Denmark11,471
Norway8,966
Finland7,563
Iceland1,107
Greenland168
Faroe107
Åland18

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma117,456
RedLine93,057
Vidar56
Unknown10
Top 5 countries by number of victims
CountryNumber of victims
Peru7,306
Turkey7,176
India6,307
Pakistan6,285
Vietnam5,822
Nordic region countries
CountryNumber of victims
Norway142
Sweden96
Denmark47
Finland44
Iceland10

Articles/News

Multiple crypto packages hijacked, turned into info-stealers

  • https://www.sonatype.com/blog/multiple-crypto-packages-hijacked-turned-into-info-stealers

EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware

  • https://thehackernews.com/2025/03/encrypthub-exploits-windows-zero-day-to.html

Binance CSO: Understanding Recent Credential Leaks and the Rise of InfoStealer Malware

  • https://www.binance.com/en/blog/security/binance-cso-understanding-recent-credential-leaks-and-the-rise-of-infostealer-malware-646085240367972382

StealC V2 – A Major Update to a Popular Infostealer

  • https://cryptolek.info/2025/03/30/stealc-v2-a-major-update-to-a-popular-infostealer/