Security researchers reported sustained infostealer activity centered on Lumma Stealer and Vidar, with operators distributing malware through fake CAPTCHA lures, pirated software downloads, phishing emails, and poisoned search results. AhnLab said July 2026 campaigns commonly delivered Remus, LummaC2, ACRStealer, and Vidar via cracked software hosted on services including mega.nz, Amazon S3, and MediaFire, while Microsoft and other well-known brands were frequently impersonated. TrendAI separately described fake verification pages that trick victims into pasting malicious commands into the Windows Run dialog, leading to multistage infections that deployed Lumma Stealer, Rhadamanthys, AsyncRAT, XWorm, and Emmenhtal.
The campaigns relied on evasive execution chains using mshta.exe, obfuscated PowerShell, DLL sideloading, temporary Chromium profiles, and even MP3 files carrying injected JavaScript to load payloads in memory and communicate with attacker-controlled infrastructure. Researchers also said Vidar Stealer 2.0 expanded its appeal with a rewritten codebase, multithreaded theft, stronger anti-analysis, and broader credential and wallet theft, helping it gain momentum as some criminals moved away from Lumma after a doxxing incident and Telegram account compromise disrupted Lumma operations and eroded trust in its malware-as-a-service ecosystem. The reporting indicates that infostealer operators are rapidly shifting delivery methods and malware families while continuing to target both enterprises and individual users for credential theft and follow-on attacks.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
During July 2026, AhnLab ASEC observed infostealers including Remus, LummaC2, ACRStealer, and Vidar commonly distributed as cracks and illegal software via services such as mega.nz, Amazon S3, and MediaFire. The report also documented MSBuild-based delivery chains and email campaigns delivering MassLogger and AgentTesla.
On October 6, 2025, the developer known as Loadbaks announced Vidar Stealer v2.0 on underground forums. The update was described as a major rewrite from C++ to C with multithreading, stronger anti-analysis, and a polymorphic builder.
On September 17, 2025, a Lumma Stealer representative reportedly posted on an underground forum that the operation's official Telegram accounts had been stolen. The compromise further disrupted communications with customers and operational coordination.
As Lumma Stealer became unstable and lost support, customers were observed discussing alternatives and migrating mainly to Vidar and StealC. Trend telemetry also showed an upward trend in Vidar file sourcing from September 13 to October 9, 2025.
Trend Micro telemetry began registering a steady decline in Lumma Stealer sample detections and command-and-control activity in early September 2025. The drop also reflected a significant reduction in targeted endpoints.
A targeted underground exposure and doxxing campaign against alleged Lumma Stealer operators began in late August 2025 and ran through early October 2025. The campaign reportedly exposed personal and operational details of five individuals on a site called "Lumma Rats."
Lumma Stealer was targeted by a coordinated international law-enforcement takedown attempt in May 2025. The operation later recovered its infrastructure and customer engagement.
Vidar originated in 2018 as an information stealer on Russian-language underground forums and initially leveraged the Arkei stealer source code.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 57 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcetrendaisecurity.com
Open sourcetrendaisecurity.com
Open sourceasec.ahnlab.com
Open sourcetrendmicro.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.