A brief look at all things infostealers for the week 18, 2025 (28.04.2025–04.05.2025). This week observed updates from LummaC2 and StealC infostealers. Grabbed some numbers from marketplaces and some interesting news/articles.
Infostealer Updates
LummaC2
Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)
Update 30.04
- Added ability to ignore certain builds by their tag
- Fixed Edge cookie and password collection
- Cleaned up WD 10/11 + Cloud
Screenshot taken from XSS forum
Update 3.05
- Added collection of crypto extensions Brave Wallet, Ctrl Wallet, Ecto Wallet, Eternl, EVER Wallet, Finnie, Goby, Hashpack, KardiaChain Wallet, Keeper Wallet, Leap Terra Wallet, MyTonWallet, Nightly, OpenMask, Oxygen, Pali Wallet, Pulse Wallet, Rainbow Wallet, Rise Wallet, Sender Wallet, SteemKeychain, TON Wallet, Tonkeeper, Uniswap Extension
- Added BrowserPass, CommonKey, Dashlane, Keeper Password Manager, MYKI, OneKey, RoboForm, Splikity password manager extensions collection
- Fixed MetaMask crypto-extensions collection
- Fixed collection of EOS Authenticator, GAuth Authenticator authenticator extensions.
- Fixed icon selection in lnk-builder
- Cleanup WD 10/11 + Cloud
Screenshot taken from XSS forum
StealC v2
Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)
Stealc v2.4.0 update
Build:
- Stab bitness changed to x32 (in 2.5.0 we will add a switch in the admin, at the moment through support build an update file for the required bitness)
- Improved builder, removed a large number of compiler settings that could interfere with the work of stubs cryptors
- A large number of minor changes in the code
Screenshot taken from XSS forum
Marketplace Updates
This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.
RussianMarket
Stealers by number of victims
Stealer name | Number of victims |
---|---|
Lumma | 8,686,296 |
RisePro | 1,429,438 |
Vidar | 1,316,629 |
StealC | 1,005,540 |
RedLine | 789,740 |
Raccoon | 329,799 |
Rhadamanthys | 24,502 |
Acreed | 19,423 |
Top 5 countries by number of victims
Country | Number of victims |
---|---|
India | 1,397,228 |
Brazil | 1,066,647 |
Indonesia | 737,353 |
Egypt | 673,373 |
Pakistan | 666,071 |
Nordic region countries
Country | Number of victims |
---|---|
Sweden | 22,600 |
Denmark | 12,024 |
Norway | 9,417 |
Finland | 7,958 |
Iceland | 1,151 |
Greenland | 172 |
Faroe | 114 |
Åland | 18 |
ExodusMarket
Stealers by number of victims
Stealer name | Number of victims |
---|---|
Lumma | 321,080 |
RedLine | 108,169 |
Vidar | 48 |
Unknown | 6,789 |
Top 5 countries by number of victims
Country | Number of victims |
---|---|
India | 44,547 |
Brazil | 28,694 |
Indonesia | 25,226 |
Philippines | 19,646 |
Turkey | 18,231 |
Nordic region countries
Country | Number of victims |
---|---|
Sweden | 914 |
Denmark | 528 |
Norway | 495 |
Finland | 342 |
Iceland | 60 |
Articles/News
Gremlin Stealer: New Stealer on Sale in Underground Forum
- https://unit42.paloaltonetworks.com/new-malware-gremlin-stealer-for-sale-on-telegram/
Finding Malware: Unveiling LUMMAC.V2 with Google Security Operations
- https://www.googlecloudcommunity.com/gc/Community-Blog/Finding-Malware-Unveiling-LUMMAC-V2-with-Google-Security/ba-p/899110
Yet Another NodeJS Backdoor (YaNB): A Modern Challenge
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/yet-another-nodejs-backdoor-yanb-a-modern-challenge/
Uncovering MintsLoader With Recorded Future Malware Intelligence Hunting
- https://www.recordedfuture.com/research/uncovering-mintsloader-with-recorded-future-malware-intelligence-hunting
TerraStealerV2 and TerraLogger: Golden Chickens’ New Malware Families Discovered
- https://www.recordedfuture.com/research/terrastealerv2-and-terralogger
Threat Actors are Targeting US Tax-Session with new Tactics of Stealerium-infostealer
- https://www.seqrite.com/blog/threat-actors-are-targeting-us-tax-session-with-new-tactics-of-stealerium-infostealer/
I StealC You: Tracking the Rapid Changes To StealC
- https://www.zscaler.com/blogs/security-research/i-stealc-you-tracking-rapid-changes-stealc