216.73.217.22

August 2025 Infostealer Trend Report

· Published 16/09/2025 13:40 · Modified 16/09/2025 14:40

Export JSON

Essential information

Published
16/09/2025 13:40
Modified
16/09/2025 14:40
Tags
2025-09-16 acrstealer dll sideloading domain masquerading infostealer lummac2 rhadamanthys seo poisoning slack
Related entities
9 techniques (mitre), 3 malware

Description

This analysis examines trends in August 2025, focusing on distribution volume, methods, and disguises. AhnLab's automated systems collect and analyze malware, providing real-time IOC services. Infostealers, often disguised as cracks, are distributed through . Notable variants include , , and . Distribution methods evolved from personal blogs to legitimate websites, bypassing search engine restrictions. Malware is primarily distributed as EXE files (89.7%) or through DLL-SideLoading (10.3%). Two significant trends emerged: mass distribution via Marketplace and 's technique, which now targets security company domains to evade detection.

External references