All things infostealers. Week 19, 2025


A brief look at all things infostealers for the week 19, 2025 (05.05.2025–11.05.2025). This week observed updates from LummaC2 infostealer. Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

LummaC2

Note: The update posts are copy-pasted as is (and machine-translated if post wasn’t available in English, possibly with some minor edits by me)

Update 5.05

  1. Added API token system, now you can manage issued tokens, share method permissions among services

Screenshot from XSS forum

Update 8.05

  1. Added ability to specify admin id in team settings to accept requests to join directly in Telegram
  2. Fixed LevelDB collection for Coinbase crypto extension
  3. Cleaned WD 10/11 + Cloud

Screenshot from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma8,796,399
RisePro1,429,405
Vidar1,332,728
StealC1,005,459
RedLine789,687
Raccoon329,731
Acreed46,823
Rhadamanthys24,479
Top 5 countries by number of victims
CountryNumber of victims
India1,410,817
Brazil1,075,442
Indonesia742,733
Egypt678,276
Pakistan671,212
Nordic region countries
CountryNumber of victims
Sweden22,936
Denmark12,194
Norway9,587
Finland8,059
Iceland1,166
Greenland174
Faroe116
Åland18

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma307,159
RedLine96,326
Vidar43
Unknown7,653
Top 5 countries by number of victims
CountryNumber of victims
India40,378
Brazil27,425
Indonesia23,063
Philippines17,607
Turkey16,842
Nordic region countries
CountryNumber of victims
Sweden869
Denmark506
Norway378
Finland311
Iceland53

Articles/News

Lumma Stealer, coming and going

  • https://news.sophos.com/en-us/2025/05/09/lumma-stealer-coming-and-going/

InfoStealer: Investigating a Massive MacOS Watering Hole Campaign with ClickFix and EtherHiding

  • https://badbyte.io/infostealer-macos-etherhiding/

New Noodlophile Stealer Distributes Via Fake AI Video Generation Platforms

  • https://www.morphisec.com/blog/new-noodlophile-stealer-fake-ai-video-generation-platforms/

Lampion Is Back With ClickFix Lures

  • https://unit42.paloaltonetworks.com/lampion-malware-clickfix-lures/

PupkinStealer : A .NET-Based Info-Stealer

  • https://www.cyfirma.com/research/pupkinstealer-a-net-based-info-stealer/