logo

September 2025 Infostealer Trend Report

ID: 88b24eab-0020-5707-a721-a684d90ea8ba

STIX ID: report--88b24eab-0020-5707-a721-a684d90ea8ba

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-10-15

Date Updated: 2026-04-26

Author: ATCP

...
...

This AhnLab SEcurity intelligence Center (ASEC) report summarizes August 2025 findings on Infostealer activity: malware is widely distributed disguised as cracks/keygens via SEO poisoning and posts on legitimate sites, with primary distribution formats being EXE and DLL sideloading (including multi-DLL chains). Notable families include LummaC2, ACRStealer, and Rhadamanthys; ASEC observed increased DLL sideloading, use of multiple malicious DLLs, and an atypical proxyware campaign masquerading as the open-source SteamCleaner (signed and installer-packed). The report also describes automated collection/analysis capabilities, C2 blocking via ATIP, and provides MD5 IOCs and additional statistics in the full ATIP report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.