All things infostealers. Week 28, 2025


A brief look at all things infostealers for the week 28, 2025 (07.07.2025–13.07.2025). This week observed updates in MonsterV2 and an emergence of a new stealer. Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

MonsterV2

[+] Added the ability to launch the stealer on all bots
[+] Added the ability to launch the stealer on selected bots
[=] Accelerated loader launch on selected bots
[=] Fixed typos in some error messages
[=] Optimization and minor improvements in the build code
[=] Fixed a bug where due to a large number of open handles in the system, browser cookies might not be collected on some machines
[!] Rebuild required!


AURA Stealer

Made a separate post. Click-click.


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, and the victim numbers in the countries of the Nordic region.

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma9,246,363
RisePro1,429,089
Vidar1,416,788
StealC1,046,928
RedLine789,316
Raccoon329,236
Acreed313,251
Rhadamanthys26,976
Top 5 countries by number of victims
CountryNumber of victims
India1,531,658
Brazil1,134,465
Indonesia787,656
Egypt721,277
Pakistan705,231
Nordic region countries
CountryNumber of victims
Sweden24,981
Denmark13,329
Norway10,498
Finland8,885
Iceland1,246
Greenland183
Faroe117
Åland21

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma473,458
Rhadamanthys77,084
RedLine35,304
Unknown13,625
StealC10,242
Vidar4,733
Top 5 countries by number of victims
CountryNumber of victims
India66,195
Brazil46,948
Indonesia35,360
USA25,527
Philippines22,972
Nordic region countries
CountryNumber of victims
Sweden1,707
Denmark970
Norway751
Finland554
Iceland86

Articles/News

NordDragonScan: Quiet Data-Harvester on Windows

  • https://www.fortinet.com/blog/threat-research/norddragonscan-quiet-data-harvester-on-windows

Fix the Click: Preventing the ClickFix Attack Vector

  • https://unit42.paloaltonetworks.com/preventing-clickfix-attack-vector/

ClickFix Chaos: A Deep Dive into Rhadamanthys Infostealer’s Stealth and Steal Tactics

  • https://darkatlas.io/blog/clickfix-chaos-a-deep-dive-into-rhadamanthys-infostealers-stealth-and-steal-tactics

GitHub Abused to Spread Malware Disguised as Free VPN

  • https://www.cyfirma.com/research/github-abused-to-spread-malware-disguised-as-free-vpn/

Combolists and ULP Files on the Dark Web: A Secondary and Unreliable Source of Information about Compromises

  • https://www.group-ib.com/blog/combolists-ulp-darkweb/