All things infostealers. Week 34, 2025


A brief look at all things infostealers for the week 34, 2025 (18.08.2025–24.08.2025). Grabbed some numbers from marketplaces and some interesting news/articles.

Infostealer Updates

¯\_(ツ)_/¯


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma6,869,208
Vidar516,574
RisePro145,573
StealC732,275
RedLine192,209
Acreed431,338
Racoon5,096
Rhadamanthys80,164
Top 5 countries by number of victims
CountryNumber of victims
India1,033,241
Brazil659,491
Indonesia510,606
Egypt443,557
Pakistan383,289
Nordic region countries
CountryNumber of victims
Sweden17,789
Denmark9,679
Norway7,836
Finland6,282
Iceland906
Greenland137
Faroe90
Åland21

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma475,382
Rhadamanthys107,810
RedLine35,139
StealC25,949
Vidar10,771
Top 5 countries by number of victims
CountryNumber of victims
India71,669
Brazil50,297
Indonesia37,109
USA28,955
Philippines24,706
Nordic region countries
CountryNumber of victims
Sweden1,910
Denmark1,050
Norway822
Finland614
Iceland85

Articles/News

Behind the Curtain: How Lumma Affiliates Operate

  • https://assets.recordedfuture.com/insikt-report-pdfs/2025/cta-2025-0820.pdf

Noodlophile Stealer Evolves: Targeted Copyright Phishing Hits Enterprises with Social Media Footprints

  • https://www.morphisec.com/blog/noodlophile-stealer-evolves-targeted-copyright-phishing-hits-enterprises-with-social-media-footprints/

Detailed Analysis of the Stealer-Traffer Ecosystem

  • https://medium.com/s2wblog/detailed-analysis-of-the-stealer-traffer-ecosystem-40ba805e1bca

A new, cheaper Mac stealer is quickly spreading on the dark web

  • https://moonlock.com/new-mac-stealer-spreading

Falcon Platform Prevents COOKIE SPIDER’s SHAMOS Delivery on macOS

  • https://www.crowdstrike.com/en-us/blog/falcon-prevents-cookie-spider-shamos-delivery-macos/

Think before you Click(Fix): Analyzing the ClickFix social engineering technique

  • https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/