All things infostealers. Week 22, 2025


A brief look at all things infostealers for the week 22, 2025 (20.05.2025–01.06.2025). This week not really eventful. Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

LummaC2

The user Lumma asked the administration of XSS forum to ban them on the forum. The chatter on the forum is that Lumma will most likely transform into private mode, rather than public MAAS.


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma8,984,984
RisePro1,429,284
Vidar1,374,200
StealC1,018,253
RedLine789,541
Raccoon329,536
Acreed153,158
Rhadamanthys24,442
Top 5 countries by number of victims
CountryNumber of victims
India1,463,621
Brazil1,100,775
Indonesia760,819
Egypt696,812
Pakistan685,746
Nordic region countries
CountryNumber of victims
Sweden23,786
Denmark12,650
Norway9,990
Finland8,403
Iceland1,209
Greenland179
Faroe117
Åland20

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma395,841
RedLine34,976
Unknown13,629
StealC5,934
Vidar956
Top 5 countries by number of victims
CountryNumber of victims
India46,690
Brazil35,990
Indonesia27,205
Philippines18,590
USA16,674
Nordic region countries
CountryNumber of victims
Sweden1,154
Denmark648
Norway487
Finland384
Iceland61

Articles/News

Chasing Eddies: New Rust- based InfoStealer used in CAPTCHA campaigns

  • https://www.elastic.co/security-labs/eddiestealer

Lumma Infostealer – Down but Not Out?

  • https://blog.checkpoint.com/security/lumma-infostealer-down-but-not-out/

StealC v2 Malware Enhances Stealth and Expands Data Theft Features

  • https://www.picussecurity.com/resource/blog/stealc-v2-malware-enhances-stealth-and-expands-data-theft-features