logo

November 2025 Infostealer Trend Report

ID: 821c8135-f862-5083-99d8-b31330db3722

STIX ID: report--821c8135-f862-5083-99d8-b31330db3722

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-12-15

Date Updated: 2026-04-26

Author: ATCP

...
...

This AhnLab ASEC report summarizes November 2025 Infostealer activity: mass distribution via cracked software and SEO-poisoning, a shift toward DLL sideloading (≈77% of samples), emergence of a new loader that downloads XOR/XOR-decrypted modules from multiple fake C2s, and increased distribution of AURA Stealer (with Base64-encoded configs and defined C2 API endpoints); the report includes C2 behavior, configuration examples, and MD5 indicators and points to ATIP services for IOCs and further analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.