All things infostealers. Week 24, 2025


A brief look at all things infostealers for the week 24, 2025 (09.06.2025–15.06.2025). This week observed updates in MonsterV2 and Bee Stealer stealers, and emergence of Fusion Stealer. Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

MonsterV2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

[=] Fixed a bug where log synchronization errors were not displayed in the panel
[=] Fixed a bug with saving bot filter states
[=] Fixed a bug where the saved state of stealer log filters was not displayed
[=] Minor optimizations in the panel code
[+] Added a geo filter to the log and bot pages
[!] Rebuild not required!

Screenshot from XSS forum


Bee Stealer

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

update
completely rewritten back/front web panel
builder .exe is now available (crypt is required, I issue captcha as before by hand)
more convenient log export
sorting table with logs

Screenshot from XSS forum


Fusion Stealer

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)
Comment: Well, the outcome of the post was pretty obvious. The thread was closed by the administration of the forum until the user makes a deposit to the forum.

This stealer is for rent, since it is still in a testing phase, therefore the price is so low.

A little about the stealer
c++ without dependencies
build weight 120-130kb (MSbuild)
The output is a native file that is very easy to crypt.

Collects
Chrome Firefox Opera Edge Brave (Passwords / Cookie / History)
TDATA / Discord / VPN / FTP
Crypto
Exodus Zcash Electrum Atomic
System information about PC

Client-side decryption, data is sent to TG with protection from log hijacking.

At the moment the cost is 35$/month.

CIS countries are blocked.

Screenshot from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma9,058,562
RisePro1,429,206
Vidar1,373,973
StealC1,018,142
RedLine789,449
Raccoon329,406
Acreed213,067
Rhadamanthys24,430
Top 5 countries by number of victims
CountryNumber of victims
India1,480,308
Brazil1,109,191
Indonesia767,018
Egypt702,457
Pakistan690,906
Nordic region countries
CountryNumber of victims
Sweden24,125
Denmark12,689
Norway10,121
Finland8,545
Iceland1,216
Greenland182
Faroe117
Åland20

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma446,942
RedLine35,103
Rhadamanthys24,361
Unknown13,628
StealC7,771
Vidar4,207
Top 5 countries by number of victims
CountryNumber of victims
India55,793
Brazil39,991
Indonesia31,350
Philippines20,372
USA19,406
Nordic region countries
CountryNumber of victims
Sweden1,384
Denmark802
Norway594
Finland466
Iceland75

Articles/News

Demystifying Myth Stealer: A Rust Based InfoStealer

  • https://www.trellix.com/en-in/blogs/research/demystifying-myth-stealer-a-rust-based-infostealer/

Amos hiding in GitHub

  • https://medium.com/walmartglobaltech/amos-hiding-in-github-199eabea6605

Understanding Katz Stealer Malware and Its Credential Theft Capabilities

  • https://www.picussecurity.com/resource/blog/understanding-katz-stealer-malware-and-its-credential-theft-capabilities

Dozens arrested across Asia in global infostealer malware crackdown

  • https://therecord.media/dozens-arrested-infostealer-interpol-crackdown