All things infostealers. Week 36, 2025


A brief look at all things infostealers for the week 36, 2025 (01.09.2025–07.09.2025). Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

¯\_(ツ)_/¯


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma6,924,445
Vidar526,715
RisePro145,560
StealC732,184
RedLine192,197
Acreed476,327
Racoon5,095
Rhadamanthys122,434
Top 5 countries by number of victims
CountryNumber of victims
India1,059,216
Brazil667,674
Indonesia517,299
Egypt450,543
Pakistan389,898
Nordic region countries
CountryNumber of victims
Sweden18,175
Denmark9,924
Norway8,021
Finland6,436
Iceland933
Greenland137
Faroe90
Åland21

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma475,352
Rhadamanthys107,759
RedLine35,139
StealC26,712
Vidar11,639
Top 5 countries by number of victims
CountryNumber of victims
India71,763
Brazil50,468
Indonesia37,174
USA29,021
Philippines24,793
Nordic region countries
CountryNumber of victims
Sweden1,915
Denmark1,052
Norway825
Finland612
Iceland85

Articles/News

Unmasked: Salat Stealer – A Deep Dive into Its Advanced Persistence Mechanisms and C2 Infrastructure

  • https://www.cyfirma.com/research/unmasked-salat-stealer-a-deep-dive-into-its-advanced-persistence-mechanisms-and-c2-infrastructure/

Threat Actors Impersonate Microsoft Teams To Deliver Odyssey macOS Stealer Via Clickfix

  • https://www.cloudsek.com/blog/threat-actors-impersonate-microsoft-teams-to-deliver-odyssey-macos-stealer-via-clickfix

Not Safe for Work: Tracking and Investigating Stealerium and Phantom Infostealers

  • https://www.proofpoint.com/us/blog/threat-insight/not-safe-work-tracking-and-investigating-stealerium-and-phantom-infostealers