Vidar
π΄ Activeπͺ Windows Β· since 2018 Β· Malware-as-a-service Β· aka Vidar Stealer
A fork of the older Arkei stealer, in circulation since 2018. Trend Micro reported it as one of the main replacements chosen by Lumma customers in late 2025.
Version 2.0, rewritten in C, was announced on 6 October 2025, and the Australian Cyber Security Centre warned of ClickFix campaigns delivering Vidar in May 2026.
π¦ How it spreads
ClickFix via compromised WordPress sitescracked software and keygens via SEO poisoning
π What it takes
browser passwords and cookiescrypto walletscloud service tokensDiscord and Telegram dataSteam sessions
Remus
π΄ Activeπͺ Windows Β· since 2026 Β· Malware-as-a-service Β· aka REMUS
Gen Digital attributes Remus to the Lumma lineage as a 64-bit variant, citing near-identical obfuscation and browser encryption bypass code; it resolves its command servers through Ethereum smart contracts. The developer denies it is a Lumma rebrand.
Observed in the wild since February 2026 and distributed through ClickFix and cracked-software campaigns through mid 2026.
π¦ How it spreads
ClickFix via compromised WordPress sitescracked software and keygens via SEO poisoning
π What it takes
browser passwordssession cookies and tokenscrypto walletspassword manager extension dataclipboard contents
Atomic macOS Stealer
π΄ Activeπ macOS Β· since 2023 Β· Malware-as-a-service Β· aka AMOS, Atomic Stealer
Sold on Telegram for 1,000 US dollars a month from April 2023. Sophos says it accounted for almost 40 percent of its macOS protection updates in 2025.
Still delivered through ClickFix and fake utility lures in 2026, and recent builds add persistence and remote command support.
π¦ How it spreads
ClickFix Terminal commandsfake or cracked app installersmalvertisingpoisoned AI chat search results
π What it takes
Keychain passwordsbrowser passwords and cookiescrypto walletsApple Notesfiles
Formbook / XLoader
π΄ Activeπͺ Windows π macOS Β· since 2016 Β· Malware-as-a-service Β· aka Formbook, XLoader
Formbook went on sale in February 2016 and was rebranded as XLoader in 2020, when it was sold only as a hosted service and gained a macOS build.
Among the most submitted families on MalwareBazaar in 2026.
π¦ How it spreads
phishing email attachments
π What it takes
browser passwordskeystrokesscreenshotsfiles
SalatStealer
π΄ Activeπͺ Windows Β· since 2025 Β· Malware-as-a-service Β· aka Salat Stealer, WEB_RAT
Written in Go and sold by Russian-speaking operators linked to NyashTeam. It combines data theft with remote control and live webcam and microphone streaming.
Identified by CYFIRMA in August 2025 and still reported to ThreatFox and MalwareBazaar in 2026.
π¦ How it spreads
fake game cheats and cracks on YouTubemalicious archives on open-source repositories
π What it takes
browser passwordscrypto walletsTelegram and Steam sessionskeystrokesscreenshots and webcam
Agent Tesla
π΄ Activeπͺ Windows Β· since 2014 Β· Commercial keylogger with leaked builders Β· aka AgentTesla, Negasteal
A .NET keylogger first seen in late 2014 that exfiltrates over SMTP, FTP or Telegram. Unit 42 tracks OriginLogger as its direct successor.
Its seller closed in March 2019, but builders remain in circulation and it is the most submitted stealer family on MalwareBazaar.
π¦ How it spreads
phishing email attachmentsmalicious Office documents
π What it takes
browser passwordsemail client credentialsFTP and VPN credentialskeystrokesscreenshots
StealC
π§ Disruptedπͺ Windows Β· since 2023 Β· Malware-as-a-service Β· aka Stealc
Sold by a developer known as Plymouth since January 2023, with version 2 released in March 2025. The June 2026 action against StealC, Amadey and SocGholish recovered 27 million compromised data sets.
Targeted by Operation Endgame in June 2026 alongside the Amadey loader; new StealC indicators continued to be reported to ThreatFox in the following months.
π¦ How it spreads
Amadey loaderfake cracked software on YouTube
π What it takes
browser passwords and cookiescrypto walletsmessenger and email client dataVPN credentialsscreenshots
π Disruptions
- 2026-06-24 Operation Endgame: German BKA and partners from Belgium, Denmark, France, the Netherlands, the UK, the US and Canada, coordinated by Europol and Eurojust, neutralised 326 servers and 142 domains used by StealC, Amadey and SocGholish during a 15 to 19 June action week; Microsoft DCU filed a parallel civil action against the shared infrastructure.
PureLogs
π΄ Activeπͺ Windows Β· since 2022 Β· Subscription sale by developer PureCoder Β· aka PureLog Stealer, PureLogs Stealer
Part of the Pure family of tools from the developer PureCoder and usually delivered by the PureCrypter loader. Recent campaigns targeted healthcare, government, hospitality and education.
Trend Micro documented a multistage PureLog campaign using copyright-notice lures in March 2026.
π¦ How it spreads
phishing emailPureCrypter droppermalvertising
π What it takes
browser passwords and cookiescrypto walletsemail clientsFTP and VPN credentialsscreenshots
Lumma
π Rebuilt after disruptionπͺ Windows Β· since 2022 Β· Malware-as-a-service Β· aka LummaC2, Lumma Stealer, LummaC2 Stealer
Microsoft counted over 394,000 infected Windows computers between March and May 2025, and the FBI identified at least 1.7 million instances of Lumma stealing data. Gen Digital attributes the 2026 Remus stealer to the same code lineage.
Infrastructure returned within weeks of the May 2025 takedown, then activity fell from September 2025 after a doxxing campaign against alleged core members, with many customers moving to Vidar and StealC.
π¦ How it spreads
ClickFix fake CAPTCHAmalvertisingphishing emailcracked softwareGitHub-hosted fake tools
π What it takes
browser passwordssession cookiescrypto wallets and extensionsVPN, email and FTP client datauser documents
π Disruptions
- 2025-05-21 Microsoft DCU obtained a court order and took down, suspended or blocked about 2,300 Lumma domains; the DOJ and FBI seized five control-panel domains between 19 and 21 May; Europol EC3 and Japan's JC3 suspended locally based infrastructure.
MacSync
π΄ Activeπ macOS Β· since 2025 Β· Malware-as-a-service Β· aka MacSync Stealer, Mac.c
Began as Mac.c in April 2025, was sold and renamed MacSync a month later, and added a Go-based backdoor.
Microsoft and Zscaler documented MacSync ClickFix campaigns in 2026, including Google ads that led to shared Claude chats with malicious Terminal commands.
π¦ How it spreads
ClickFix Terminal commandsmalvertisingfake utility sitescracked apps
π What it takes
Keychain databrowser passwordscrypto walletsSSH keys and cloud credentialsfiles
ACR Stealer
π΄ Activeπͺ Windows Β· since 2024 Β· Malware-as-a-service Β· aka ACRStealer
Hides its command server behind dead-drop pages on Steam, Telegraph and Google Docs. Proofpoint identified Amatera as a rebranded, improved version.
Distribution rose sharply in 2025 and it was still among the main stealers AhnLab saw in June 2026.
π¦ How it spreads
cracked software and keygensSEO poisoning
π What it takes
browser passwords and cookiescrypto wallet extensionsemail and FTP client dataVPN configurationspassword managers
RedLine
π§ Disruptedπͺ Windows Β· since 2020 Β· Malware-as-a-service Β· aka RedLine Stealer, RECORDSTEALER
First advertised on Russian-language forums in early 2020 and long one of the most widespread stealers. ESET found over 1,000 IP addresses hosting RedLine panels and concluded that RedLine and META share a creator.
Operation Magnus took down core servers in October 2024 and gave authorities a database of the service's clients.
π¦ How it spreads
malvertisingphishing emailfraudulent software downloadsmalicious sideloading
π What it takes
browser passwords and cookiessaved credit cardscrypto walletsSteam, Discord and Telegram dataVPN client data
π Disruptions
- 2024-10-28 Operation Magnus: Dutch National Police with the FBI and other US agencies, coordinated through Eurojust, took down three servers in the Netherlands and seized two domains; the US unsealed charges against alleged RedLine developer Maxim Rudometov and two people were taken into custody in Belgium.
META Stealer
π§ Disruptedπͺ Windows Β· since 2022 Β· Malware-as-a-service Β· aka META, MetaStealer
Launched in March 2022 as a RedLine clone that claimed the same code and panel. ESET concluded that RedLine and META share a creator.
Taken down together with RedLine in Operation Magnus in October 2024.
π¦ How it spreads
malvertisingphishing emailfraudulent software downloadsmalicious sideloading
π What it takes
browser passwordssession cookiessaved credit cardscrypto walletssystem information
π Disruptions
- 2024-10-28 Operation Magnus: Dutch National Police with the FBI and other US agencies, coordinated through Eurojust, took down RedLine and META servers in the Netherlands, seized two command domains and Telegram accounts, and retrieved a database of the two services' clients.
Raccoon
π Rebuilt after disruptionπͺ Windows Β· since 2019 Β· Malware-as-a-service Β· aka Raccoon Stealer, RaccoonStealer, Racealer, Mohazo
Leased for about 200 US dollars a month according to the DOJ. Sokolovsky pleaded guilty and was sentenced to 60 months in US federal prison in December 2024.
Version 1 went offline in March 2022 when an operator was arrested; a rewritten version 2 was on sale by May 2022 and the group announced version 2.3.0 in August 2023.
π¦ How it spreads
phishing emailfake software installers
π What it takes
browser passwords and cookiessaved credit cardscrypto walletsfilesscreenshots
π Disruptions
- 2022-03 Dutch authorities arrested Ukrainian national Mark Sokolovsky while the FBI and police in Italy and the Netherlands dismantled the infrastructure behind Raccoon version 1.
- 2022-10-25 The DOJ unsealed an indictment against Sokolovsky and the FBI opened a site for people to check whether their email address was in more than 50 million stolen credentials it had collected.
Rhadamanthys
π§ Disruptedπͺ Windows Β· since 2022 Β· Malware-as-a-service
A modular stealer sold since September 2022 that builds on its authors' earlier Hidden Bee project. Europol said its main suspect had access to over 100,000 victim crypto wallets.
Operation Endgame took its infrastructure offline in November 2025, after a 2025 surge in use following the Lumma takedown.
π¦ How it spreads
malvertising for fake software sitesClickFix fake CAPTCHAfake cracks on YouTube
π What it takes
browser datacrypto walletsemail and messenger dataFTP and SSH client credentialspassword manager and 2FA data
π Disruptions
- 2025-11-13 Operation Endgame: Europol and Eurojust coordinated authorities from 11 countries in a 10 to 13 November action that took down 1,025 servers and seized 20 domains linked to Rhadamanthys, VenomRAT and the Elysium botnet.
RisePro
β°οΈ Defunctπͺ Windows Β· since 2022 Β· Malware-as-a-service
Flashpoint assessed it as very likely a clone of Vidar when it surfaced in December 2022; its logs were sold on the Russian Market shop.
No public research on new RisePro campaigns has appeared since 2024, and the most recent MalwareBazaar sample tagged RisePro dates from April 2025.
π¦ How it spreads
PrivateLoader pay-per-installcracked software on GitHub
π What it takes
passwordssaved credit cardspersonal data
Banshee
β°οΈ Defunctπ macOS Β· since 2024 Β· Stealer-as-a-service Β· aka Banshee Stealer
Check Point found a build that encrypted its strings with the same algorithm Apple uses in XProtect, and those samples went undetected on VirusTotal for over two months.
The operator shut the service down on 24 November 2024, a day after its source code leaked; Check Point saw campaigns using the updated builds continue into December 2024.
π¦ How it spreads
phishing sites impersonating popular softwaremalicious GitHub repositories
π What it takes
browser passwordscrypto wallets and extensionsKeychain datamacOS login passwordfiles
Poseidon
β°οΈ Defunctπ macOS Β· since 2024 Β· Malware-as-a-service Β· aka Poseidon Stealer, RodStealer, Rodrigo Stealer
Rebranded from RodStealer in June 2024 by the developer Rodrigo4 and shares much of its code with Atomic Stealer.
Its developer sold the project in fall 2024 and the new owner relaunched it as Odyssey Stealer.
π¦ How it spreads
malvertising for fake app downloadsmalicious DMG installers
π What it takes
browser datacrypto walletsBitwarden and KeePassXC dataVPN configurationsfiles
Cryptbot
π§ Disruptedπͺ Windows Β· since 2019 Β· Commodity stealer spread by paid distributors Β· aka CryptBot
Google estimated it infected about 670,000 computers in the year before its lawsuit, spread through tampered versions of software such as Google Earth Pro and Chrome.
Google's 2023 court action targeted its distributors; Mandiant still saw it delivered in a 2024 campaign.
π¦ How it spreads
modified copies of popular softwarepirated movie downloadsphishing email
π What it takes
browser passwords and cookiescrypto walletssaved credit cardssocial media loginsscreenshots
π Disruptions
- 2023-04-26 Google obtained a temporary restraining order in the Southern District of New York against CryptBot distributors believed to be based in Pakistan, allowing it to take down their distribution domains.
Amatera
π΄ Activeπͺ Windows Β· since 2024 Β· Malware-as-a-service Β· aka Amatera Stealer
A rebrand of ACR Stealer whose panel first surfaced in December 2024. It talks to its servers through low-level Windows sockets to avoid hooked network APIs.
In active development when Proofpoint reported on it in June 2025, with new indicators still reported to ThreatFox in 2026.
π¦ How it spreads
ClearFake web injectsClickFix fake CAPTCHA
π What it takes
browser passwords and cookiescrypto walletspassword manager extensionsemail and messenger dataSSH and FTP files
Odyssey
π΄ Activeπ macOS Β· since 2025 Β· Malware-as-a-service Β· aka Odyssey Stealer
The relaunch of Poseidon under a new owner, adding anti-sandbox checks and persistence that Atomic Stealer later copied.
Reported in ClickFix campaigns through 2025 on spoofed finance, crypto news and App Store sites.
π¦ How it spreads
ClickFix fake CAPTCHAfake Homebrew and GitHub pages
π What it takes
browser passwords and cookiescrypto walletsKeychain passwordsfiles