A brief look at all things infostealers for the week 32, 2025 (04.08.2025–10.08.2025). Grabbed some numbers from marketplaces and some interesting news/articles.
Infostealer Updates
¯\_(ツ)_/¯
Marketplace Updates
This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.
Marketplace Updates Spreadsheet
Russian Market
Stealers by number of victims
| Stealer name | Number of victims |
|---|---|
| Lumma | 6,837,552 |
| Vidar | 510,597 |
| RisePro | 145,581 |
| StealC | 728,762 |
| RedLine | 192,220 |
| Acreed | 376,290 |
| Racoon | 5,096 |
| Rhadamanthys | 58,104 |
Top 5 countries by number of victims
| Country | Number of victims |
|---|---|
| India | 1,015,903 |
| Brazil | 651,608 |
| Indonesia | 505,106 |
| Egypt | 437,550 |
| Pakistan | 378,277 |
Nordic region countries
| Country | Number of victims |
|---|---|
| Sweden | 17,452 |
| Denmark | 9,534 |
| Norway | 7,667 |
| Finland | 6,161 |
| Iceland | 893 |
| Greenland | 135 |
| Faroe | 89 |
| Åland | 21 |
Exodus Market
Stealers by number of victims
| Stealer name | Number of victims |
|---|---|
| Lumma | 480,153 |
| Rhadamanthys | 108,136 |
| RedLine | 35,347 |
| Unknown | 26,384 |
| StealC | 24,236 |
| Vidar | 10,534 |
Top 5 countries by number of victims
| Country | Number of victims |
|---|---|
| India | 74,333 |
| Brazil | 51,465 |
| Indonesia | 38,046 |
| USA | 30,402 |
| Philippines | 25,659 |
Nordic region countries
| Country | Number of victims |
|---|---|
| Sweden | 1,934 |
| Denmark | 1,064 |
| Norway | 838 |
| Finland | 624 |
| Iceland | 91 |
Articles/News
PyLangGhost RAT: Rising Stealer from Lazarus Group Striking Finance and Technology
- https://any.run/cybersecurity-blog/pylangghost-malware-analysis/
Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem
- https://www.sentinelone.com/labs/ghost-in-the-zip-new-pxa-stealer-and-its-telegram-powered-ecosystem/
Unveiling a New Variant of the DarkCloud Campaign
- https://www.fortinet.com/blog/threat-research/unveiling-a-new-variant-of-the-darkcloud-campaign