February 2025 Infostealer Trend Report
ID: 0a3b9c25-ce70-53bc-b307-86e6b31ec88f
STIX ID: report--0a3b9c25-ce70-53bc-b307-86e6b31ec88f
Feed Name: ASEC
AhnLab’s report summarizes February 2025 telemetry on Infostealer distribution: actors use SEO-poisoned ‘crack’ posts hosted on legitimate forums and cloud services (Mega, Mediafire, Box) to distribute stealers (LummaC2, Vidar, ACRStealer, etc.). Trends include a decline in true DLL side-loading but increased use of multi-file packages meant to appear authentic, a resurgence of Vidar with a password-protected GUI execution method that evades sandbox analysis, and provided IOCs (MD5s) and C2-blocking actions via ATIP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
