All things infostealers. Week 43, 2025


A brief look at all things infostealers for the week 43, 2025 (20.10.2025–26.10.2025). Observed updates in AID_Stealer and AURA Stealer. Grabbed some numbers from marketplaces and few interesting news/articles for you to read.

Infostealer Updates

AID_Stealer

SMALL FIX

1) General refactoring of the stub code + managed to slightly reduce the build weight.
2) Fixed and updated the pinning option for builds with a resident module (removed and replaced the garbage method).

Screenshot from BHF


AURA Stealer

Minor update

Build updated:

  • Updated collection of the latest versions of Edge and Brave browsers
  • Build remorphing

Panel update:

  • General optimization of panel performance
  • Regular database maintenance and index optimization performed

Screenshot from BHF


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma6,982,231
Vidar603,229
RisePro145,539
StealC765,416
RedLine192,171
Acreed760,687
Raccoon5,085
Rhadamanthys364,660
Top 5 countries by number of victims
CountryNumber of victims
India1,130,566
Brazil711,995
Indonesia546,053
Egypt474,572
Pakistan408,454
Nordic region countries
CountryNumber of victims
Sweden20,254
Denmark11,050
Norway8,951
Finland7,261
Iceland1,029
Greenland149
Faroe97
Åland22

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma474,444
Rhadamanthys106,983
RedLine35,070
StealC26,446
Vidar11,354
Top 5 countries by number of victims
CountryNumber of victims
India71,724
Brazil50,420
Indonesia37,155
USA28,725
Philippines24,767
Nordic region countries
CountryNumber of victims
Sweden1,911
Denmark1,050
Norway818
Finland603
Iceland83

Articles/News

“How do I kill a process with Powershell?”

  • https://playing-with-fire-101-nb6sb.ondigitalocean.app/pwf201.html

Fast, Broad, and Elusive: How Vidar Stealer 2.0 Upgrades Infostealer Capabilities

  • https://www.trendmicro.com/en_us/research/25/j/how-vidar-stealer-2-upgrades-infostealer-capabilities.html

Analysis of the Lumma infostealer

  • https://www.genians.co.kr/en/blog/threat_intelligence/lumma-infostealer

RedTiger: New Red Teaming Tool in the Wild Targeting Gamers and Discord Accounts

  • https://www.netskope.com/blog/redtiger-new-red-teaming-tool-in-the-wild-targeting-gamers-and-discord-accounts

Dissecting YouTube’s Malware Distribution Network

  • https://research.checkpoint.com/2025/youtube-ghost-network/