All things infostealers. Week 30, 2025


A brief look at all things infostealers for the week 30, 2025 (21.07.2025–27.07.2025). I had some issues with accessing to the XSS forum due to well-known developments, therefore, no Infostealer updates. Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

¯\_(ツ)_/¯


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

RussianMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma9,323,005
Vidar1,442,120
RisePro1,429,021
StealC1,059,201
RedLine789,264
Acreed347,076
Racoon329,117
Rhadamanthys30,219
Top 5 countries by number of victims
CountryNumber of victims
India1,550,927
Brazil1,144,305
Indonesia795,101
Egypt728,040
Pakistan713,121
Nordic region countries
CountryNumber of victims
Sweden25,451
Denmark13,490
Norway10,664
Finland9,053
Iceland1,259
Greenland184
Faroe118
Åland22

ExodusMarket

Stealers by number of victims
Stealer nameNumber of victims
Lumma473,392
Rhadamanthys101,472
RedLine35,354
Unknown23,183
StealC16,658
Vidar7,242
Top 5 countries by number of victims
CountryNumber of victims
India70,605
Brazil49,827
Indonesia37,083
USA28,865
Philippines24,709
Nordic region countries
CountryNumber of victims
Sweden1,846
Denmark1,020
Norway794
Finland592
Iceland87

Articles/News

Back to Business: Lumma Stealer Returns with Stealthier Methods

  • https://www.trendmicro.com/en_us/research/25/g/lumma-stealer-returns.html

New Advanced Stealer (SHUYAL) Targets Credentials Across 19 Popular Browsers

  • https://hybrid-analysis.blogspot.com/2025/07/new-advanced-stealer-shuyal-targets.html

The Rise of Acreed Infostealer in the Post-LummaC2 Threat Landscape

  • https://www.bitsight.com/blog/the-rise-of-acreed-infostealer

Startup takes personal data stolen by malware and sells it on to other companies

  • https://www.malwarebytes.com/blog/news/2025/07/startup-takes-personal-data-stolen-by-malware-and-sells-it-on-to-other-companies

Hacker sneaks infostealer malware into early access Steam game

  • https://www.bleepingcomputer.com/news/security/hacker-sneaks-infostealer-malware-into-early-access-steam-game/