logo

February 2025 Infostealer Trend Report

ID: 0a3b9c25-ce70-53bc-b307-86e6b31ec88f

STIX ID: report--0a3b9c25-ce70-53bc-b307-86e6b31ec88f

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-03-10

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab’s report summarizes February 2025 telemetry on Infostealer distribution: actors use SEO-poisoned ‘crack’ posts hosted on legitimate forums and cloud services (Mega, Mediafire, Box) to distribute stealers (LummaC2, Vidar, ACRStealer, etc.). Trends include a decline in true DLL side-loading but increased use of multi-file packages meant to appear authentic, a resurgence of Vidar with a password-protected GUI execution method that evades sandbox analysis, and provided IOCs (MD5s) and C2-blocking actions via ATIP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.