All things infostealers. Week 49, 2025


A brief look at all things infostealers for the week 49, 2025 (01.12.2025–07.12.2025). Added update from StealCV2 stealer. Grabbed some numbers from marketplaces and few interesting news/articles for you to read.

Infostealer Updates

StealC Stealer

Stealc v2.9.0 update

Build:

  • Steam token collection has been restored; tokens are now decrypted from files without the need to inject into the Steam process (tokens are collected from all accounts that the user is logged into, not just the active one)
  • Improved file transfer to the server
  • Runtime cleanup
  • Other minor code fixes

Gate:

  • Improved file retrieval from build

Database:

  • Added Perplexity Comet browser collection
  • Added IndexedDB collection for all MetaMask versions

Admin panel:

  • Added a function to delete all logs from the server in the Admin -> Server Management section
  • A function to delete temporary log files has been added to the Admin -> Server Management section
  • A function to delete empty logs has been added to the Admin -> Server Management section
  • The ability to select the message type (plain text, text with screenshot, or ZIP file of log) has been added to the user notification settings
  • Added the ability to select the message type (plain text, text with screenshot, or ZIP file of log) for chat lists (Admin -> Telegram Bot) to the Telegram bot settings

Worker panel:

  • Added bulk exports for workers

Screenshot from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,013,897
Vidar780,831
RisePro145,532
StealC806,496
RedLine192,129
Acreed835,100
Raccoon5,080
Rhadamanthys474,944
Top 5 countries by number of victims
CountryNumber of victims
India1,197,442
Brazil734,358
Indonesia562,680
Egypt487,798
Pakistan415,689
Nordic region countries
CountryNumber of victims
Sweden21,988
Denmark11,981
Norway9,820
Finland8,054
Iceland1,109
Greenland154
Faroe105
Åland24

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma473,825
Rhadamanthys106,478
RedLine35,011
StealC26,238
Vidar12,192
Top 5 countries by number of victims
CountryNumber of victims
India72,209
Brazil50,393
Indonesia37,140
USA28,504
Philippines24,776
Nordic region countries
CountryNumber of victims
Sweden1,905
Denmark1,037
Norway816
Finland601
Iceland83

Articles/News

Arkanix Stealer: Newly discovered short term profit malware

  • https://www.gdatasoftware.com/blog/2025/12/38306-arkanix-stealer

macOS Stealers: How Modern Infostealers Harvest Credentials

  • https://deceptiq.com/blog/macos-stealers-technical-analysis