All things infostealers. Week 16, 2025


A brief look at all things infostealers for the week 16, 2025 (14.04.2025–20.04.2025). This week observed updates from LummaC2 and StealC infostealers. Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Update 13.04

  1. Added bot functionality for teams in the Corporate plan
  2. The following functionality is available when creating Telegram bot: enable sending logs to a worker in a private message, choose whether to send a file to him or not, automatically create a worker link when a request is approved, create a single chat for sending all logs and choose whether to send a file there or not
  3. Added the ability to format the message as you wish, all variables from Telegram knock are supported
  4. Available start message (when entering the command /start), as well as 9 buttons in the keyboard, it will be sent after approval of the application and when entering the command /start
  5. Added “Change” button at the block of participants allows you to select default settings for team members: set delay and allow loading. The same settings will be taken into account in the worker link

Screenshot taken from XSS forum

Update 13.04

  1. Fixed error when defining HWID
  2. Clean WD 10/11 + Cloud

Screenshot taken from XSS forum

Update 14.04

  1. Added processing of restrictions on sending a message when knocking in Telegram
  2. Added subscription relevance check in API
  3. Improved indexing of log requests in the market when placing for sale
  4. Improved Sticky Notes collection and processing

Screenshot taken from XSS forum

Update 15.04

  1. Fixed “TigerVNC” collection
  2. Cleaned WD 10/11 + Cloud

Screenshot taken from XSS forum

Update 16.04

  1. Cleaning WD 10/11 + Cloud + Run-Time

Screenshot taken from XSS forum

Update 18.04

  1. Added /id command to get chat id in the bot for “Teams”
  2. Removed the limit on uploading logs. It is important to take into account the more logs when uploading, the longer it takes
  3. Fixed a problem when a delay in Telegram could affect the panel’s functionality.
  4. Cleaning WD 10/11 + Cloud + Run-Time

Screenshot taken from XSS forum


StealC

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Update stealc v2.1.0

Build:

  • reworked sending heavy files (last metamask update)
  • now files are transferred in chunks of 256kb
  • rewrote networking on wininet

Admin panel:

  • changed logic for detecting duplicates for last 24 hours
  • fixed ignoring duplicates by HWID
  • changed calculation of log weight on logs page
  • fixed link in telegram bot to download logs
  • added statistics page

Screenshot taken from XSS forum

Update stealc v2.2.0

Build:

  • continue to improve the delivery of files from builds to the server, added control of missing blocks with several attempts to resend
  • returned rc4 encryption between build and server
  • old builds will NOT work with the new admin panel

admin panel:

  • !!!! added Google Chrome v135 password decryption
  • added (or rather, returned from v1) to the log information display to display build start path, system language, keyboard layout list, Windows version, CPU model (also cores/threads), amount of RAM, video card model
  • improved built-in update functionality
  • fixed bug, which could incorrectly install gate updates through the admin panel interface
  • cookies inside the log are now duplicated in json in addition to netscape
  • removed the fake error page, by which reservers could detect the host
  • fixed log upload mass in admin panel
  • fixed wallet counting, now counts not the number of files, but the number of wallets
  • fixed %WALLETS_LIST% enumeration in telegram-bot
  • fixed duplicate messages about incoming logs in telegram-bot

Screenshot taken from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma8,498,052
RisePro1,429,493
Vidar1,310,230
StealC1,005,675
RedLine789,826
Raccoon329,953
Rhadamanthys24,550
Acreed18,768
Top 5 countries by number of victims
CountryNumber of victims
India1,372,681
Brazil1,052,438
Indonesia726,698
Egypt665,172
Pakistan656,510
Nordic region countries
CountryNumber of victims
Sweden22,253
Denmark11,803
Norway9,282
Finland7,838
Iceland1,141
Greenland171
Faroe111
Åland18

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma271,855
RedLine118,426
Vidar55
Unknown2,922
Top 5 countries by number of victims
CountryNumber of victims
India39,190
Brazil23,427
Indonesia21,712
Philippines16,585
Turkey16,290
Nordic region countries
CountryNumber of victims
Sweden713
Norway438
Denmark429
Finland281
Iceland47

Articles/News

Deep Dive into Infostealer Payloads and Evasion – Part 2

  • https://erdalozkaya.com/deep-dive-into-infostealer-payloads/

Byte Bandits: How Fake PDF Converters Are Stealing More Than Just Your Documents

  • https://www.cloudsek.com/blog/byte-bandits-how-fake-pdf-converters-are-stealing-more-than-just-your-documents