All things infostealers. Week 45, 2025


A brief look at all things infostealers for the week 45, 2025 (03.11.2025–09.11.2025). Observed updates in AID_Stealer. Grabbed some numbers from marketplaces and few interesting news/articles for you to read.

Infostealer Updates

AID_Stealer

UPDATE
1) Added Crypto Clipper for 14 wallets.

https[://]imgur[.]com/a/Bk9ynKk

Mechanics:
a) With the resident build, the clipper works as part of the stabilizer and sends reports of successful replacements to the panel + if the Telegram bot is enabled in the panel, reports will also be sent to the chat.
b) With the regular build, the clipper will be installed in the system as a separate application and will continue to work offline.
c) This option is optional.
2) Changed the time format in cookies for correct import into cookie managers.
3) Fixed Critical process.
4) Improved builder.

Screenshot from BHF


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,002,460
Vidar650,607
RisePro145,536
StealC783,842
RedLine192,159
Acreed802,525
Raccoon5,083
Rhadamanthys413,009
Top 5 countries by number of victims
CountryNumber of victims
India1,149,078
Brazil720,830
Indonesia552,251
Egypt479,664
Pakistan411,521
Nordic region countries
CountryNumber of victims
Sweden20,978
Denmark11,445
Norway9,353
Finland7,586
Iceland1,073
Greenland150
Faroe98
Åland23

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma474,160
Rhadamanthys106,782
RedLine35,040
StealC26,321
Vidar11,281
Top 5 countries by number of victims
CountryNumber of victims
India71,712
Brazil50,410
Indonesia37,152
USA28,611
Philippines24,752
Nordic region countries
CountryNumber of victims
Sweden1,907
Denmark1,039
Norway816
Finland601
Iceland83

Articles/News

ClickFix Attacks Against macOS Users Evolving

  • https://www.securityweek.com/clickfix-attacks-against-macos-users-evolving/

Nikkei Says 17,000 Impacted by Data Breach Stemming From Slack Account Hack

  • https://www.securityweek.com/nikkei-says-17000-impacted-by-data-breach-stemming-from-slack-account-hack/

MUT-4831: Trojanized npm packages deliver Vidar infostealer malware

  • https://securitylabs.datadoghq.com/articles/mut-4831-trojanized-npm-packages-vidar/

Approaching stealers devs: a brief interview with AURA

  • https://g0njxa.medium.com/approaching-stealers-devs-a-brief-interview-with-aura-9b513369e117