← Pwnsy Data

πŸͺ Infostealer Tracker

The malware behind most stolen logins and session cookies. Live activity from ThreatFox and MalwareBazaar over the last 48 hours, every family's takedowns and disruptions, the platforms it hits, how it spreads and what it takes.

Families tracked
21
6 target macOS
Seen in 48 hours
11
families with live indicators or samples
Stealer indicators
463
of 7,159 in ThreatFox, 48h
Disruptions logged
8
latest 2026-06-24
πŸ“Š Live activity
ThreatFox indicators (C2 servers and delivery URLs) plus MalwareBazaar samples, last 48 hours
Vidar
184 ind Β· 11 smp
Remus
90 ind Β· 12 smp
Atomic macOS Stealer
70 ind Β· 1 smp
Formbook / XLoader
9 ind Β· 25 smp
SalatStealer
15 ind Β· 7 smp
Agent Tesla
0 ind Β· 14 smp
StealC
11 ind Β· 0 smp
PureLogs
1 ind Β· 5 smp
Lumma
5 ind Β· 0 smp
MacSync
3 ind Β· 0 smp
ACR Stealer
1 ind Β· 1 smp
RedLine
quiet
META Stealer
quiet
Raccoon
quiet
Rhadamanthys
quiet
RisePro
quiet
Banshee
quiet
Poseidon
quiet
Cryptbot
quiet
Amatera
quiet
Odyssey
quiet
ThreatFox indicatorsMalwareBazaar samples
Other stealer-named families in ThreatFox: Unknown Stealer (46), stealler (12), Venus Stealer (12), RN Stealer (3), Phemedrone Stealer (1)
πŸš” Disruption timeline
Takedowns, seizures and arrests, newest first
2026-06-24StealC: Operation Endgame: German BKA and partners from Belgium, Denmark, France, the Netherlands, the UK, the US and Canada, coordinated by Europol and Eurojust, neutralised 326 servers and 142 domains used by StealC, Amadey and SocGholish during a 15 to 19 June action week; Microsoft DCU filed a parallel civil action against the shared infrastructure. source β†—
2025-11-13Rhadamanthys: Operation Endgame: Europol and Eurojust coordinated authorities from 11 countries in a 10 to 13 November action that took down 1,025 servers and seized 20 domains linked to Rhadamanthys, VenomRAT and the Elysium botnet. source β†—
2025-05-21Lumma: Microsoft DCU obtained a court order and took down, suspended or blocked about 2,300 Lumma domains; the DOJ and FBI seized five control-panel domains between 19 and 21 May; Europol EC3 and Japan's JC3 suspended locally based infrastructure. source β†—
2024-10-28RedLine: Operation Magnus: Dutch National Police with the FBI and other US agencies, coordinated through Eurojust, took down three servers in the Netherlands and seized two domains; the US unsealed charges against alleged RedLine developer Maxim Rudometov and two people were taken into custody in Belgium. source β†—
2024-10-28META Stealer: Operation Magnus: Dutch National Police with the FBI and other US agencies, coordinated through Eurojust, took down RedLine and META servers in the Netherlands, seized two command domains and Telegram accounts, and retrieved a database of the two services' clients. source β†—
2023-04-26Cryptbot: Google obtained a temporary restraining order in the Southern District of New York against CryptBot distributors believed to be based in Pakistan, allowing it to take down their distribution domains. source β†—
2022-10-25Raccoon: The DOJ unsealed an indictment against Sokolovsky and the FBI opened a site for people to check whether their email address was in more than 50 million stolen credentials it had collected. source β†—
2022-03Raccoon: Dutch authorities arrested Ukrainian national Mark Sokolovsky while the FBI and police in Italy and the Netherlands dismantled the infrastructure behind Raccoon version 1. source β†—
πŸ—‚οΈ Families
21 of 21 families

Vidar

πŸ”΄ Active
πŸͺŸ Windows Β· since 2018 Β· Malware-as-a-service Β· aka Vidar Stealer

A fork of the older Arkei stealer, in circulation since 2018. Trend Micro reported it as one of the main replacements chosen by Lumma customers in late 2025.

Version 2.0, rewritten in C, was announced on 6 October 2025, and the Australian Cyber Security Centre warned of ClickFix campaigns delivering Vidar in May 2026.
160
C2 servers Β· 48h
0
Delivery URLs Β· 48h
11
Samples Β· 48h
πŸ“¦ How it spreads
ClickFix via compromised WordPress sitescracked software and keygens via SEO poisoning
πŸŽ’ What it takes
browser passwords and cookiescrypto walletscloud service tokensDiscord and Telegram dataSteam sessions
Sources: Trend Micro, Australian Cyber Security Centre (ASD), AhnLab ASEC, Trend Micro

Remus

πŸ”΄ Active
πŸͺŸ Windows Β· since 2026 Β· Malware-as-a-service Β· aka REMUS

Gen Digital attributes Remus to the Lumma lineage as a 64-bit variant, citing near-identical obfuscation and browser encryption bypass code; it resolves its command servers through Ethereum smart contracts. The developer denies it is a Lumma rebrand.

Observed in the wild since February 2026 and distributed through ClickFix and cracked-software campaigns through mid 2026.
90
C2 servers Β· 48h
0
Delivery URLs Β· 48h
12
Samples Β· 48h
πŸ“¦ How it spreads
ClickFix via compromised WordPress sitescracked software and keygens via SEO poisoning
πŸŽ’ What it takes
browser passwordssession cookies and tokenscrypto walletspassword manager extension dataclipboard contents
Sources: Gen Digital, Flashpoint, Infosecurity Magazine (reporting eSentire research), AhnLab ASEC

Atomic macOS Stealer

πŸ”΄ Active
🍎 macOS · since 2023 · Malware-as-a-service · aka AMOS, Atomic Stealer

Sold on Telegram for 1,000 US dollars a month from April 2023. Sophos says it accounted for almost 40 percent of its macOS protection updates in 2025.

Still delivered through ClickFix and fake utility lures in 2026, and recent builds add persistence and remote command support.
4
C2 servers Β· 48h
4
Delivery URLs Β· 48h
1
Samples Β· 48h
πŸ“¦ How it spreads
ClickFix Terminal commandsfake or cracked app installersmalvertisingpoisoned AI chat search results
πŸŽ’ What it takes
Keychain passwordsbrowser passwords and cookiescrypto walletsApple Notesfiles
Sources: SentinelOne, Sophos, Microsoft Threat Intelligence

Formbook / XLoader

πŸ”΄ Active
πŸͺŸ Windows 🍎 macOS Β· since 2016 Β· Malware-as-a-service Β· aka Formbook, XLoader

Formbook went on sale in February 2016 and was rebranded as XLoader in 2020, when it was sold only as a hosted service and gained a macOS build.

Among the most submitted families on MalwareBazaar in 2026.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
25
Samples Β· 48h
πŸ“¦ How it spreads
phishing email attachments
πŸŽ’ What it takes
browser passwordskeystrokesscreenshotsfiles
Sources: Check Point Research, Malpedia (Fraunhofer FKIE)

SalatStealer

πŸ”΄ Active
πŸͺŸ Windows Β· since 2025 Β· Malware-as-a-service Β· aka Salat Stealer, WEB_RAT

Written in Go and sold by Russian-speaking operators linked to NyashTeam. It combines data theft with remote control and live webcam and microphone streaming.

Identified by CYFIRMA in August 2025 and still reported to ThreatFox and MalwareBazaar in 2026.
2
C2 servers Β· 48h
0
Delivery URLs Β· 48h
7
Samples Β· 48h
πŸ“¦ How it spreads
fake game cheats and cracks on YouTubemalicious archives on open-source repositories
πŸŽ’ What it takes
browser passwordscrypto walletsTelegram and Steam sessionskeystrokesscreenshots and webcam
Sources: CYFIRMA, SonicWall, Malpedia (Fraunhofer FKIE)

Agent Tesla

πŸ”΄ Active
πŸͺŸ Windows Β· since 2014 Β· Commercial keylogger with leaked builders Β· aka AgentTesla, Negasteal

A .NET keylogger first seen in late 2014 that exfiltrates over SMTP, FTP or Telegram. Unit 42 tracks OriginLogger as its direct successor.

Its seller closed in March 2019, but builders remain in circulation and it is the most submitted stealer family on MalwareBazaar.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
14
Samples Β· 48h
πŸ“¦ How it spreads
phishing email attachmentsmalicious Office documents
πŸŽ’ What it takes
browser passwordsemail client credentialsFTP and VPN credentialskeystrokesscreenshots
Sources: SentinelOne, Palo Alto Networks Unit 42, Check Point Research

StealC

🚧 Disrupted
πŸͺŸ Windows Β· since 2023 Β· Malware-as-a-service Β· aka Stealc

Sold by a developer known as Plymouth since January 2023, with version 2 released in March 2025. The June 2026 action against StealC, Amadey and SocGholish recovered 27 million compromised data sets.

Targeted by Operation Endgame in June 2026 alongside the Amadey loader; new StealC indicators continued to be reported to ThreatFox in the following months.
11
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
Amadey loaderfake cracked software on YouTube
πŸŽ’ What it takes
browser passwords and cookiescrypto walletsmessenger and email client dataVPN credentialsscreenshots
πŸš” Disruptions
  • 2026-06-24 Operation Endgame: German BKA and partners from Belgium, Denmark, France, the Netherlands, the UK, the US and Canada, coordinated by Europol and Eurojust, neutralised 326 servers and 142 domains used by StealC, Amadey and SocGholish during a 15 to 19 June action week; Microsoft DCU filed a parallel civil action against the shared infrastructure.
Sources: Zscaler ThreatLabz, Eurojust, Microsoft, Check Point Research

PureLogs

πŸ”΄ Active
πŸͺŸ Windows Β· since 2022 Β· Subscription sale by developer PureCoder Β· aka PureLog Stealer, PureLogs Stealer

Part of the Pure family of tools from the developer PureCoder and usually delivered by the PureCrypter loader. Recent campaigns targeted healthcare, government, hospitality and education.

Trend Micro documented a multistage PureLog campaign using copyright-notice lures in March 2026.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
5
Samples Β· 48h
πŸ“¦ How it spreads
phishing emailPureCrypter droppermalvertising
πŸŽ’ What it takes
browser passwords and cookiescrypto walletsemail clientsFTP and VPN credentialsscreenshots
Sources: Cyble, Trend Micro, Netresec

Lumma

πŸ” Rebuilt after disruption
πŸͺŸ Windows Β· since 2022 Β· Malware-as-a-service Β· aka LummaC2, Lumma Stealer, LummaC2 Stealer

Microsoft counted over 394,000 infected Windows computers between March and May 2025, and the FBI identified at least 1.7 million instances of Lumma stealing data. Gen Digital attributes the 2026 Remus stealer to the same code lineage.

Infrastructure returned within weeks of the May 2025 takedown, then activity fell from September 2025 after a doxxing campaign against alleged core members, with many customers moving to Vidar and StealC.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
ClickFix fake CAPTCHAmalvertisingphishing emailcracked softwareGitHub-hosted fake tools
πŸŽ’ What it takes
browser passwordssession cookiescrypto wallets and extensionsVPN, email and FTP client datauser documents
πŸš” Disruptions
  • 2025-05-21 Microsoft DCU obtained a court order and took down, suspended or blocked about 2,300 Lumma domains; the DOJ and FBI seized five control-panel domains between 19 and 21 May; Europol EC3 and Japan's JC3 suspended locally based infrastructure.
Sources: Microsoft, U.S. Department of Justice, Microsoft Threat Intelligence, Trend Micro

MacSync

πŸ”΄ Active
🍎 macOS · since 2025 · Malware-as-a-service · aka MacSync Stealer, Mac.c

Began as Mac.c in April 2025, was sold and renamed MacSync a month later, and added a Go-based backdoor.

Microsoft and Zscaler documented MacSync ClickFix campaigns in 2026, including Google ads that led to shared Claude chats with malicious Terminal commands.
0
C2 servers Β· 48h
2
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
ClickFix Terminal commandsmalvertisingfake utility sitescracked apps
πŸŽ’ What it takes
Keychain databrowser passwordscrypto walletsSSH keys and cloud credentialsfiles
Sources: Moonlock (MacPaw), Zscaler ThreatLabz, Microsoft Threat Intelligence

ACR Stealer

πŸ”΄ Active
πŸͺŸ Windows Β· since 2024 Β· Malware-as-a-service Β· aka ACRStealer

Hides its command server behind dead-drop pages on Steam, Telegraph and Google Docs. Proofpoint identified Amatera as a rebranded, improved version.

Distribution rose sharply in 2025 and it was still among the main stealers AhnLab saw in June 2026.
1
C2 servers Β· 48h
0
Delivery URLs Β· 48h
1
Samples Β· 48h
πŸ“¦ How it spreads
cracked software and keygensSEO poisoning
πŸŽ’ What it takes
browser passwords and cookiescrypto wallet extensionsemail and FTP client dataVPN configurationspassword managers
Sources: Malpedia (Fraunhofer FKIE), AhnLab ASEC, Proofpoint, AhnLab ASEC

RedLine

🚧 Disrupted
πŸͺŸ Windows Β· since 2020 Β· Malware-as-a-service Β· aka RedLine Stealer, RECORDSTEALER

First advertised on Russian-language forums in early 2020 and long one of the most widespread stealers. ESET found over 1,000 IP addresses hosting RedLine panels and concluded that RedLine and META share a creator.

Operation Magnus took down core servers in October 2024 and gave authorities a database of the service's clients.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
malvertisingphishing emailfraudulent software downloadsmalicious sideloading
πŸŽ’ What it takes
browser passwords and cookiessaved credit cardscrypto walletsSteam, Discord and Telegram dataVPN client data
πŸš” Disruptions
  • 2024-10-28 Operation Magnus: Dutch National Police with the FBI and other US agencies, coordinated through Eurojust, took down three servers in the Netherlands and seized two domains; the US unsealed charges against alleged RedLine developer Maxim Rudometov and two people were taken into custody in Belgium.
Sources: Proofpoint, U.S. Department of Justice, Eurojust, ESET

META Stealer

🚧 Disrupted
πŸͺŸ Windows Β· since 2022 Β· Malware-as-a-service Β· aka META, MetaStealer

Launched in March 2022 as a RedLine clone that claimed the same code and panel. ESET concluded that RedLine and META share a creator.

Taken down together with RedLine in Operation Magnus in October 2024.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
malvertisingphishing emailfraudulent software downloadsmalicious sideloading
πŸŽ’ What it takes
browser passwordssession cookiessaved credit cardscrypto walletssystem information
πŸš” Disruptions
  • 2024-10-28 Operation Magnus: Dutch National Police with the FBI and other US agencies, coordinated through Eurojust, took down RedLine and META servers in the Netherlands, seized two command domains and Telegram accounts, and retrieved a database of the two services' clients.
Sources: Malpedia (Fraunhofer FKIE), U.S. Department of Justice, ESET

Raccoon

πŸ” Rebuilt after disruption
πŸͺŸ Windows Β· since 2019 Β· Malware-as-a-service Β· aka Raccoon Stealer, RaccoonStealer, Racealer, Mohazo

Leased for about 200 US dollars a month according to the DOJ. Sokolovsky pleaded guilty and was sentenced to 60 months in US federal prison in December 2024.

Version 1 went offline in March 2022 when an operator was arrested; a rewritten version 2 was on sale by May 2022 and the group announced version 2.3.0 in August 2023.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
phishing emailfake software installers
πŸŽ’ What it takes
browser passwords and cookiessaved credit cardscrypto walletsfilesscreenshots
πŸš” Disruptions
  • 2022-03 Dutch authorities arrested Ukrainian national Mark Sokolovsky while the FBI and police in Italy and the Netherlands dismantled the infrastructure behind Raccoon version 1.
  • 2022-10-25 The DOJ unsealed an indictment against Sokolovsky and the FBI opened a site for people to check whether their email address was in more than 50 million stolen credentials it had collected.
Sources: U.S. Department of Justice, U.S. Department of Justice, Sekoia, Bitdefender

Rhadamanthys

🚧 Disrupted
πŸͺŸ Windows Β· since 2022 Β· Malware-as-a-service

A modular stealer sold since September 2022 that builds on its authors' earlier Hidden Bee project. Europol said its main suspect had access to over 100,000 victim crypto wallets.

Operation Endgame took its infrastructure offline in November 2025, after a 2025 surge in use following the Lumma takedown.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
malvertising for fake software sitesClickFix fake CAPTCHAfake cracks on YouTube
πŸŽ’ What it takes
browser datacrypto walletsemail and messenger dataFTP and SSH client credentialspassword manager and 2FA data
πŸš” Disruptions
  • 2025-11-13 Operation Endgame: Europol and Eurojust coordinated authorities from 11 countries in a 10 to 13 November action that took down 1,025 servers and seized 20 domains linked to Rhadamanthys, VenomRAT and the Elysium botnet.
Sources: Check Point Research, Europol, Malpedia (Fraunhofer FKIE), Check Point Research

RisePro

⚰️ Defunct
πŸͺŸ Windows Β· since 2022 Β· Malware-as-a-service

Flashpoint assessed it as very likely a clone of Vidar when it surfaced in December 2022; its logs were sold on the Russian Market shop.

No public research on new RisePro campaigns has appeared since 2024, and the most recent MalwareBazaar sample tagged RisePro dates from April 2025.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
PrivateLoader pay-per-installcracked software on GitHub
πŸŽ’ What it takes
passwordssaved credit cardspersonal data
Sources: Flashpoint, G DATA, Malpedia (Fraunhofer FKIE)

Banshee

⚰️ Defunct
🍎 macOS · since 2024 · Stealer-as-a-service · aka Banshee Stealer

Check Point found a build that encrypted its strings with the same algorithm Apple uses in XProtect, and those samples went undetected on VirusTotal for over two months.

The operator shut the service down on 24 November 2024, a day after its source code leaked; Check Point saw campaigns using the updated builds continue into December 2024.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
phishing sites impersonating popular softwaremalicious GitHub repositories
πŸŽ’ What it takes
browser passwordscrypto wallets and extensionsKeychain datamacOS login passwordfiles
Sources: Check Point Research, Malpedia (Fraunhofer FKIE)

Poseidon

⚰️ Defunct
🍎 macOS · since 2024 · Malware-as-a-service · aka Poseidon Stealer, RodStealer, Rodrigo Stealer

Rebranded from RodStealer in June 2024 by the developer Rodrigo4 and shares much of its code with Atomic Stealer.

Its developer sold the project in fall 2024 and the new owner relaunched it as Odyssey Stealer.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
malvertising for fake app downloadsmalicious DMG installers
πŸŽ’ What it takes
browser datacrypto walletsBitwarden and KeePassXC dataVPN configurationsfiles
Sources: Malwarebytes, Zscaler (Red Canary)

Cryptbot

🚧 Disrupted
πŸͺŸ Windows Β· since 2019 Β· Commodity stealer spread by paid distributors Β· aka CryptBot

Google estimated it infected about 670,000 computers in the year before its lawsuit, spread through tampered versions of software such as Google Earth Pro and Chrome.

Google's 2023 court action targeted its distributors; Mandiant still saw it delivered in a 2024 campaign.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
modified copies of popular softwarepirated movie downloadsphishing email
πŸŽ’ What it takes
browser passwords and cookiescrypto walletssaved credit cardssocial media loginsscreenshots
πŸš” Disruptions
  • 2023-04-26 Google obtained a temporary restraining order in the Southern District of New York against CryptBot distributors believed to be based in Pakistan, allowing it to take down their distribution domains.
Sources: Google, Google Cloud (Mandiant), ANY.RUN

Amatera

πŸ”΄ Active
πŸͺŸ Windows Β· since 2024 Β· Malware-as-a-service Β· aka Amatera Stealer

A rebrand of ACR Stealer whose panel first surfaced in December 2024. It talks to its servers through low-level Windows sockets to avoid hooked network APIs.

In active development when Proofpoint reported on it in June 2025, with new indicators still reported to ThreatFox in 2026.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
ClearFake web injectsClickFix fake CAPTCHA
πŸŽ’ What it takes
browser passwords and cookiescrypto walletspassword manager extensionsemail and messenger dataSSH and FTP files
Sources: Proofpoint, Malpedia (Fraunhofer FKIE)

Odyssey

πŸ”΄ Active
🍎 macOS · since 2025 · Malware-as-a-service · aka Odyssey Stealer

The relaunch of Poseidon under a new owner, adding anti-sandbox checks and persistence that Atomic Stealer later copied.

Reported in ClickFix campaigns through 2025 on spoofed finance, crypto news and App Store sites.
0
C2 servers Β· 48h
0
Delivery URLs Β· 48h
0
Samples Β· 48h
πŸ“¦ How it spreads
ClickFix fake CAPTCHAfake Homebrew and GitHub pages
πŸŽ’ What it takes
browser passwords and cookiescrypto walletsKeychain passwordsfiles
Sources: CYFIRMA, Zscaler (Red Canary)

Check whether a company's staff and customers show up in stealer logs with the Stealer Exposure Check, then cut stolen sessions with the Session Kill Switch. Background: what an infostealer takes and how ClickFix spreads them.