Infostealer malware continues to expose enterprise credentials, browser sessions, API keys and developer artifacts at scale, despite major law-enforcement disruption efforts. Analysis of roughly 44 million compromised-host logs collected from June 2024 through June 2026 found that most takedowns displaced operators to alternative stealer families rather than reducing the overall market. The coordinated action against LummaC2 was the exception: its sustained decline was linked to simultaneous disruption of infrastructure, distribution, monetization and criminal-market trust. Earlier Lumma campaigns used fake CAPTCHA pages to induce PowerShell execution and deploy the stealer, illustrating the social-engineering delivery methods still used to seed credential theft.
The expanding malware-as-a-service market lowers the barrier for new operators. A recently analyzed Python-based builder can create customized Windows stealers that collect Chromium and Firefox data, Wi-Fi credentials, Discord tokens, Roblox cookies, and host details before sending results to attacker-controlled Discord or Telegram webhooks; it also supports anti-analysis checks and Run-key or scheduled-task persistence. Research covering 170,298 victims found stolen credentials affecting government, military, law-enforcement, financial, remote-access and university services, with credential reuse and overlap with phishing and ransomware victims increasing repeat-compromise risk. For enterprises, compromised developer endpoints are particularly consequential because stolen cloud CLI caches, browser tokens, CI/CD secrets, service-account keys and AI-platform sessions can enable access to AWS, Azure, GCP, source-code repositories and AI tools while bypassing MFA through hijacked authenticated sessions.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers submitted a paper describing a privacy-preserving dataset representing 170,298 infostealer victims from multiple malware families. The study found credential reuse, exposure affecting high-value and security-critical organizations, and overlap between infostealer, phishing, and ransomware victim populations.
The FBI, U.S. Department of Justice, Europol, and Microsoft took action against LummaC2. Flare found LummaC2 log volume fell 46% in the following two weeks and remained 39% below baseline over the subsequent 90 days; total infostealer-log volume was also significantly lower after the action.
Operation Magnus targeted the RedLine and META infostealer families. Flare's later analysis found RedLine activity tripled and total infostealer-market volume rose 70% during the 90 days following the operation.
K7 Labs analyzed a nested archive containing TokenGrabberBuilder, a Python-based builder that embeds an operator-configured Discord or Telegram webhook and produces customized Windows infostealer payloads. The payload steals browser data, Wi-Fi passwords, Discord tokens, Roblox cookies, and system data, then stages the data in an in-memory ZIP archive for webhook exfiltration.
Flare found no measurable response by Rhadamanthys to Operation Endgame Phase 3 because it had negligible dataset volume. The analysis associated the operation with a 41% increase in total infostealer-market volume at 90 days, while cautioning that background market growth could contribute.
Flare's analysis found LummaC2 activity grew 75% during the 90 days after Operation Secure, despite LummaC2 having been named as a target of that operation.
An analysis documented a Lumma Stealer chain in which a fake CAPTCHA copied a hidden Base64-encoded PowerShell command to victims' clipboards. The loader retrieved additional scripts and a ZIP archive, launched a masquerading Set-up.exe, and appeared to establish persistence from a roaming-profile location.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 35 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
wiz.io
Open sourceflare.io
Open sourcearxiv.org
Open sourcemalware.news
Open sourcerecordedfuture.com
Open sourcemandarnaik016.in
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.