All things infostealers. Week 52, 2025


A brief look at all things infostealers for the week 52, 2025 (22.12.2025–28.12.2025). Updates in MioLab and Misericorde stealers. Grabbed some numbers from marketplaces and few interesting news/articles for you to read.

Uh-huh, the last week of the year 2025! Thanks to all the humans who visited my blog. I hope, my low quality/effort blog posts were somewhat useful to you.

I probably could have written some sort of an end-of-year recap type post, but in that case, it wouldn’t be a low quality/effort blogging, would it be? 😉

Anyhoo. Stay safe, hugs, and see you in the next year!

Infostealer Updates

MioLab Stealer

Now we will be writing about updates in this channel.

Some people had problems installing ClickFix scripts, so we created a 1-click utility that will make your life easier.
You just enter your server data and you’ll get the command without leaving the panel.

Since the release of the MacOS product, we’ve made a lot of different updates that we didn’t write about.

  1. Fixed the note grabber.
  2. Made a correct grab of Google tokens.
  3. Added several desktop wallets.
  4. Updated the panel design and the view of the logs.
  5. Added even more customization options to the .dmg builds, now you can disable the fake error.
  6. Recompiled the Ledger & Trezor modules taking into account the new updates, making them “universal”.
  7. Fixed the product’s compatibility with very old versions of MacOS.

In the New Year, we’re expecting many more updates and a couple of new products.

Screenshot taken from MioLab Products Telegram channel


Misericorde Stealer

Version 1.0.1 has just been released.

The list of changes:

  • Added the possibility of flexible configuration for Filegrabber, the ability to specify your own unique paths, depth, file extensions, minimum and maximum file weights.
  • Google Token Refresh has been added, now you can restore Google Tokens and update gmail cookies directly on the dashboard, there is support for SOCKS5 proxy(DEBUG tab has been moved to the settings section)
  • Sorter functionality has been added to LOGS tab, now you can sort the queries you need without leaving the panel – The ability to sort Cookies by domain, passwords by domain, collect Telegram tdata, Google Tokens, Steam Tokens, Wallets(including paswords from the log)/
  • New buttons have been added for interacting with logs, now you can open the log of interest directly from the panel, or delete it.
  • Now the panel supports the API, you can integrate the panel into your projects.
    With our API, you can get global panel statistics, get information about the latest logs, download logs, generate a client file.

~API documentation is attached with the panel~

Screenshot taken from BHF forum

Version 1.0.2 has just been released.

The list of changes:

Panel changes:

  • Added the function to sort Discord tokens via SORTER in logs tab
  • Added the function to connect your local API server for telegram (Allows panels to send archives weighing more than 50MB directly to your channel)
  • Added a feature for customizing telegram notifications, now you can customize your notification when sending it to your channel.

Client changes:

  • Fixed discord tokens grab
  • Fixed IP address parsing, added additional IP api services to get a valid IP address (0.0.0.0 archives should no longer be available)
  • Fixed errors that occur when the client is crypted, now the client configuration will not be lost when file is crypted. If you still have any problems with the file crypt, please let us know what exactly is going wrong.

Screenshot taken from BHF forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,013,106
Vidar877,707
RisePro145,530
StealC806,406
RedLine192,119
Acreed837,757
Raccoon5,078
Rhadamanthys508,290
Top 5 countries by number of victims
CountryNumber of victims
India1,205,805
Brazil744,170
Indonesia566,466
Egypt489,378
Pakistan416,688
Nordic region countries
CountryNumber of victims
Sweden22,726
Denmark12,407
Norway10,210
Finland8,349
Iceland1,131
Greenland155
Faroe111
Åland24

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma6,663
Rhadamanthys6,443
RedLine3
StealC9,608
Vidar6,420
Top 5 countries by number of victims
CountryNumber of victims
India3,905
Brazil2,016
Turkey1,772
USA1,757
Bangladesh1,657
Nordic region countries
CountryNumber of victims
Sweden92
Denmark42
Norway44
Finland33
Iceland4

Articles/News

From ClickFix to code signed: the quiet shift of MacSync Stealer malware

  • https://www.jamf.com/blog/macsync-stealer-evolution-code-signed-swift-malware-analysis/

DriverFixer0428 macOS Credential Stealer

  • https://www.lunchm0n3y.com/blogs-1/driverfixer0428-macos-credential-stealer