All things infostealers. Week 31, 2025


A brief look at all things infostealers for the week 31, 2025 (28.07.2025–03.08.2025). I was traveling and had an unexpected vacation at work, did not have time to search and update information on the infostealers. Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

¯\_(ツ)_/¯


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma9,340,548
Vidar1,451,158
RisePro1,428,988
StealC1,065,649
RedLine789,222
Acreed353,955
Racoon329,079
Rhadamanthys30,157
Top 5 countries by number of victims
CountryNumber of victims
India1.554,604
Brazil1,147,145
Indonesia796,498
Egypt729,581
Pakistan714,551
Nordic region countries
CountryNumber of victims
Sweden25,598
Denmark13,551
Norway10,728
Finland9,109
Iceland1,272
Greenland184
Faroe119
Åland23

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma480,182
Rhadamanthys108,193
RedLine35,356
Unknown26,385
StealC19,749
Vidar9,296
Top 5 countries by number of victims
CountryNumber of victims
India74,151
Brazil51,241
Indonesia37,952
USA30,067
Philippines25,608
Nordic region countries
CountryNumber of victims
Sweden1,912
Denmark1,051
Norway823
Finland617
Iceland89

Articles/News

LLM-Based Identification of Infostealer Infection Vectors from Screenshots: The Case of Aurora

  • https://www.arxiv.org/abs/2507.23611

MaaS Appeal: An Infostealer Rises From The Ashes

  • https://www.elastic.co/security-labs/maas-appeal-an-infostealer-rises-from-the-ashes

FAKE TELEGRAM PREMIUM SITE DISTRIBUTES NEW LUMMA STEALER VARIANT

  • https://www.cyfirma.com/research/fake-telegram-premium-site-distributes-new-lumma-stealer-variant/