All things infostealers. Week 40, 2025


A brief look at all things infostealers for the week 40, 2025 (29.09.2025–05.10.2025). Spotted only update in XFiles infostealer. Grabbed some numbers from marketplaces and some interesting news/articles.

Note: The update posts are copy-pasted as is (and machine-translated with DeepL.com if post wasn’t available in English, possibly with some minor edits by me).

Infostealer Updates

XFiles

4.0.0:
Added the ability to use personal proxies (frontends) for stealer, without support.

  • They are generated using AI, which increases their credibility.
  • Personal proxies cost from $3 to $15; the higher the price, the less harmful they appear to AV (Windows Defender, etc.).
  • Added a proxy guide.
  • Added the ability to have your own private gateway.
  • TG bot – file encryption without support.

Screenshot from XSS forum


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma6,962,684
Vidar552,458
RisePro145,551
StealC746,422
RedLine192,187
Acreed585,811
Raccoon5,086
Rhadamanthys265,369
Top 5 countries by number of victims
CountryNumber of victims
India1,092,879
Brazil689,296
Indonesia532,370
Egypt463,680
Pakistan398,225
Nordic region countries
CountryNumber of victims
Sweden19,097
Denmark10,451
Norway8,455
Finland6,829
Iceland979
Greenland140
Faroe93
Åland22

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma474,747
Rhadamanthys107,206
RedLine35,106
StealC26,542
Vidar11,447
Top 5 countries by number of victims
CountryNumber of victims
India71,738
Brazil50,442
Indonesia37,164
USA28,802
Philippines24,774
Nordic region countries
CountryNumber of victims
Sweden1,914
Denmark1,050
Norway820
Finland605
Iceland83

Articles/News

Rhadamanthys 0.9.x – walk through the updates

  • https://research.checkpoint.com/2025/rhadamanthys-0-9-x-walk-through-the-updates/

Detour Dog: DNS Malware Powers Strela Stealer Campaigns

  • https://blogs.infoblox.com/threat-intelligence/detour-dog-dns-malware-powers-strela-stealer-campaigns/