216.73.216.30

June 2026 Infostealer Trend Report

· Published 15/07/2026 13:58

Export JSON

Essential information

Published
15/07/2026 13:58
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
acrstealer agenttesla amos blockchain c2 clickfix credential theft darkcloud dll side-loading email campaign infostealer lummac2 macos targeting remus seo poisoning vidar
Related entities
5 indicators, 3 observables, 20 techniques (mitre), 7 malware

Description

During June 2026, multiple families including , , , and were distributed through techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed and through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks.

External references