All things infostealers. Week 48, 2025


A brief look at all things infostealers for the week 48, 2025 (24.11.2025–30.11.2025). AID_Stealer update from last week was missing, added for this week. Grabbed some numbers from marketplaces and few interesting news/articles for you to read.

Infostealer Updates

AID_Stealer

UPDATE
https[:]//imgur[.]com/a/hSTPH6w

1) Added decryption of Yandex Browser passwords (tested with the current version 25.8.5.983).
2) Improved thread safety in the RAT panel (removed red cross).
3) Other minor improvements and fixes + slightly increased build size.

Screenshot from BHF forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,011,213
Vidar734,361
RisePro145,532
StealC801,485
RedLine192,134
Acreed835,616
Raccoon5,081
Rhadamanthys467,217
Top 5 countries by number of victims
CountryNumber of victims
India1,185,823
Brazil730,833
Indonesia560,088
Egypt486,517
Pakistan414,737
Nordic region countries
CountryNumber of victims
Sweden21,704
Denmark11,835
Norway9,689
Finland7,950
Iceland1,100
Greenland154
Faroe103
Åland24

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma473,914
Rhadamanthys106,521
RedLine35,017
StealC26,256
Vidar12,211
Top 5 countries by number of victims
CountryNumber of victims
India72,213
Brazil50,398
Indonesia37,140
USA28,516
Philippines24,777
Nordic region countries
CountryNumber of victims
Sweden1,905
Denmark1,038
Norway816
Finland601
Iceland83

Articles/News

StealC V2 Campaign Targeting Blender Users via Malicious .blend Files

  • https://www.morphisec.com/blog/morphisec-thwarts-russian-linked-stealc-v2-campaign-targeting-blender-users-via-malicious-blend-files/

Dissecting a new malspam chain delivering Purelogs infostealer

  • https://securityaffairs.com/185066/cyber-crime/dissecting-a-new-malspam-chain-delivering-purelogs-infostealer.html