All things infostealers. Week 51, 2025


A brief look at all things infostealers for the week 51, 2025 (15.12.2025–21.12.2025). Spotted announcement of a new infostealers, and updates in MioLab and StealCv2 stealers. Grabbed some numbers from marketplaces and few interesting news/articles for you to read.

Infostealer Updates

MioLab Stealer

We added a video of the ledger module in action and uploaded it to Streamable for those who don’t use Telegram.

https[://]streamable[.]com/f70vi3 – web panel
https[://]streamable[.]com/dlsyog – work and log
https[://]streamable[.]com/eut6pl – ledger

Screenshot taken from XSS forum


Misericorde Stealer


StealC Stealer

Stealc v2.10.0 update

Build:

  • Fixed a bug in obtaining the path to config.vdf, now Steam tokens are always collected correctly
  • Minor code fixes and improvements
  • Runtime cleanup

Admin panel:

  • Completely redesigned authorization, now works with cookies with the ability to save the session (remember me – will no longer log you out every 15-30 minutes, BUT now only one session is possible per user for security reasons)
  • Fixed a bug that prevented files from being uploaded from the About Log window
  • Added a notification in case of imminent subscription expiration (just so you don’t forget)

Worker panel:
A global rework of worker functions has been carried out

  • Added the ability to use multiple builds with one worker
  • The Cookie Restore and Builder tabs are now available to workers
  • Workers now have the ability to edit their build settings

Gate:

  • Fixed bugs in processing http headers of IP addresses

API:

  • Global rework of user rights for functions, not just admin/non-admin plugins for the entire API class (to support some functions now available to workers)

Screenshot taken from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,013,339
Vidar845,749
RisePro145,529
StealC806,433
RedLine192,122
Acreed834,500
Raccoon5,079
Rhadamanthys487,096
Top 5 countries by number of victims
CountryNumber of victims
India1,203,463
Brazil740,163
Indonesia565,249
Egypt488,765
Pakistan416,217
Nordic region countries
CountryNumber of victims
Sweden22,466
Denmark12,266
Norway10,056
Finland8,215
Iceland1,124
Greenland155
Faroe107
Åland24

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma473,650
Rhadamanthys106,340
RedLine34,995
StealC26,207
Vidar12,155
Top 5 countries by number of victims
CountryNumber of victims
India72,206
Brazil50,390
Indonesia37,140
USA28,470
Philippines24,773
Nordic region countries
CountryNumber of victims
Sweden1,896
Denmark1,036
Norway809
Finland601
Iceland83

Articles/News

Defeating AuraStealer: Practical Deobfuscation Workflows for Modern Infostealers

  • https://www.gendigital.com/blog/insights/research/defeating-aurastealer-obfuscation

SantaStealer is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums

  • https://www.rapid7.com/blog/post/tr-santastealer-is-coming-to-town-a-new-ambitious-infostealer-advertised-on-underground-forums/

Stealka stealer: the new face of game cheats, mods, and cracks

  • https://www.kaspersky.com/blog/windows-stealer-stealka/55058/

I am not a robot: ClickFix used to deploy StealC and Qilin

  • https://www.sophos.com/en-us/blog/i-am-not-a-robot-clickfix-used-to-deploy-stealc-and-qilin