All things infostealers. Week 46, 2025


A brief look at all things infostealers for the week 46, 2025 (10.11.2025–16.11.2025). Grabbed some numbers from marketplaces and few interesting news/articles for you to read.

Infostealer Updates

¯\_(ツ)_/¯


Marketplace Updates

This section provides some numbers taken from the marketplaces, which include numbers of victims based on stealers, top 5 countries, the victim numbers in the countries of the Nordic region. In addition, see the CryptPad spreadsheet for all more broad numbers.

Marketplace Updates Spreadsheet

Russian Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma7,003,691
Vidar669,900
RisePro145,536
StealC789,022
RedLine192,146
Acreed806,520
Raccoon5,082
Rhadamanthys452,713
Top 5 countries by number of victims
CountryNumber of victims
India1,155,441
Brazil725,487
Indonesia555,404
Egypt481,847
Pakistan411,962
Nordic region countries
CountryNumber of victims
Sweden21,332
Denmark11,643
Norway9,509
Finland7,761
Iceland1,086
Greenland152
Faroe98
Åland24

Exodus Market

Stealers by number of victims
Stealer nameNumber of victims
Lumma474,122
Rhadamanthys106,710
RedLine35,035
StealC26,290
Vidar11,265
Top 5 countries by number of victims
CountryNumber of victims
India71,710
Brazil50,404
Indonesia37,152
USA28,561
Philippines24,751
Nordic region countries
CountryNumber of victims
Sweden1,907
Denmark1,039
Norway816
Finland601
Iceland83

Articles/News

Rhadamanthys infostealer disrupted as cybercriminals lose server access

  • https://www.bleepingcomputer.com/news/security/rhadamanthys-infostealer-disrupted-as-cybercriminals-lose-server-access/

Increase in Lumma Stealer Activity Coincides with Use of Adaptive Browser Fingerprinting Tactics

  • https://www.trendmicro.com/en_us/research/25/k/lumma-stealer-browser-fingerprinting.html

EVALUSION Campaign Delivers Amatera Stealer and NetSupport RAT

  • https://www.esentire.com/blog/evalusion-campaign-delivers-amatera-stealer-and-netsupport-rat

Digit stealer: a JXA-based infostealer that leaves little footprint

  • https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/