All things infostealers. Week 17, 2025


A brief look at all things infostealers for the week 17, 2025 (21.04.2025–27.04.2025). This week observed updates from LummaC2 and StealC infostealers. Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Update 23.04

  1. Added new method of collecting Chromium browsers, new collection of cookies, passwords, CVC/CVV codes, restor-tokens, etc. not requiring execution from the administrator
  2. Maximum price per log in the marketplace is now 100$
  3. Added rate translation on the marketplace page
  4. Fixed return of logs from the marketplace to the panel in case of large volume
  5. Added option to hide the statistics page
  6. Added NordVPN, OpenVPN to search by applications
  7. Fixed sending logs to Telegram when the archive may not match the description (not a full archive was sent).
  8. Fixed Chrome Beta build
  9. Cleaned WD 10/11 + Cloud

Screenshot taken from XSS forum

Update 25.04

  1. Reworked LNK-builder, added support for PDF/TXT/MKV/MP3/PNG/DOCX/PPTX/XLSX icons
  2. Cleaned LNK-builder

Screenshot taken from XSS forum

Update 26.04

  1. Cleaned WD 10/11 + Cloud

StealC V2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Update stealc v2.3.0

Admin panel:

  • added Brute.txt file to the root of the log – contains a list of unique passwords in the log
  • added cookie_list.txt file to the root of the log – contains a list of unique domains in cookies in the log.
  • improved tokens functionality – now correctly highlights specified domains in both passwords and cookies
  • improved search by tokens – now search correctly processes a large number of domains
  • fixed tg-bot, now tokens are correctly listed in the message
  • fixed tg-bot, now the list of wallets is correctly listed in the message
  • fixed creation of administrators (now when creating a user with admin rights he is automatically assigned access to all builds)
  • improved mass-upload of logs from the panel, added possibility to upload all logs on request (Download button next to Search button)
  • Download now responds to download/no download items
  • decrypted MetaMask seed now also displays the password that matches the wallet.

Screenshot taken from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma8,598,392
RisePro1,429,464
Vidar1,310,089
StealC1,005,600
RedLine789,787
Raccoon329,889
Rhadamanthys24,521
Acreed19,161
Top 5 countries by number of victims
CountryNumber of victims
India1,384,890
Brazil1,060,117
Indonesia732,430
Egypt669,348
Pakistan661,181
Nordic region countries
CountryNumber of victims
Sweden22,474
Denmark11,915
Norway9,365
Finland7,907
Iceland1,146
Greenland172
Faroe114
Åland18

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma321,762
RedLine118,422
Vidar54
Unknown6,199
Top 5 countries by number of victims
CountryNumber of victims
India42,710
Brazil27,598
Indonesia24,609
Philippines19,053
Turkey17,763
Nordic region countries
CountryNumber of victims
Sweden904
Denmark526
Norway496
Finland338
Iceland56

Articles/News

Lumma Stealer – Tracking distribution channels

  • https://securelist.com/lumma-fake-captcha-attacks-analysis/116274/

Infostealer Malware FormBook Spread via Phishing Campaign – Part I

  • https://www.fortinet.com/blog/threat-research/infostealer-malware-formbook-spread-via-phishing-campaign-part-i

Unmasking the Evolving Threat: A Deep Dive into the Latest Version of Lumma InfoStealer with Code Flow Obfuscation

  • https://www.trellix.com/blogs/research/a-deep-dive-into-the-latest-version-of-lumma-infostealer/

LummaStealer: The Invisible Thief in Your Network

  • https://istrosec.com/blog/lumma-stealer-en/

From GitHub to Your Clipboard — Lumma Stealer Threat Hunting and Infrastructure Analysis

  • https://medium.com/@cyb3r-hawk/lumma-stealer-threat-hunting-and-infrastructure-analysis-6e62a0e44c71

From Shadow to Spotlight: The Evolution of LummaStealer and Its Hidden Secrets

  • https://www.cybereason.com/blog/threat-analysis-lummastealer-2.0

Malware Source Code Released (Sryxen Paid)