Infostealer Malware Groups | How Lumma, RedLine, Vidar, StealC, Raccoon and Other Stealers Work (and How to Detect and Remove Them)

Infostealer malware groups are distinct malware families, such as Lumma, RedLine, Vidar, StealC, and Raccoon, that steal saved passwords, session cookies, and crypto wallets from infected devices and sell them as ready-made logs. Most are rented out as Malware-as-a-Service, so one family can run thousands of separate campaigns through different criminals.
The scale is large. In May 2025, Microsoft reported identifying more than 394,000 Windows computers infected by Lumma alone in just two months, before a coordinated takedown disrupted its infrastructure. Takedowns like that rarely end a family for good, because the code and the customers move on to the next one.
This guide covers each major family in turn: what it is, how it spreads, what it takes, how to spot it, and whether it is still active. It also covers the macOS stealers, the credential-stealing trojans and keyloggers, and the remote access trojans often deployed alongside them. If you want the fundamentals first, start with our infostealer malware guide.
The Infostealer Landscape at a Glance
In 2026, Vidar is the most-used infostealer family; Lumma and StealC are still active, and law enforcement has disrupted RedLine, Raccoon, and Rhadamanthys. Atomic Stealer leads on macOS. The market reshuffles quickly, and in the first two months of 2026, Vidar rose from fourth place to account for more than 73% of infected hosts and devices.
Active vs. Disrupted vs. Rebranded Families
An infostealer family is active when operators still sell access and new infections appear weekly. Vidar, StealC, Lumma, and Atomic Stealer fall here. Lumma was hit by a takedown in May 2025 but was rebuilt, and Vidar filled the gap left by the takedowns of Lumma and Rhadamanthys.
A family is disrupted when law enforcement seizes its infrastructure or arrests its developer. RedLine and Meta Stealer were hit in late 2024, and Rhadamanthys was hit in November 2025 (Operation Endgame). Disruption rarely ends a family completely. After the Rhadamanthys action, its developer began trying a comeback about three weeks later, though most customers had already moved to competitors.
A family is rebranded when the same codebase comes back under a new name or version. FormBook returned as XLoader, Raccoon returned as Raccoon Stealer v2, and Meta Stealer is a RedLine offshoot. The takeaway for defenders is that a takedown headline does not remove the threat, so indicators for a disrupted family stay relevant.
Comparison Table (Platform, Model, Delivery, Status)
The table below summarizes the 14 families covered in this guide. “MaaS” means Malware-as-a-Service, where the operator rents the Malware and its control panel to customers.
| Family | Platform | Model | Primary Delivery | Status |
|---|---|---|---|---|
| Vidar | Windows | MaaS | Malvertising, fake software sites, ClickFix | Active, market leader |
| Lumma (LummaC2) | Windows | MaaS | Fake CAPTCHA/ClickFix, cracked software | Disrupted May 2025, rebuilt |
| StealC | Windows | MaaS | Cracked software, malvertising, ClickFix | Active (v2) |
| RedLine | Windows | MaaS and low-cost licenses | Cracked software, phishing, malvertising | Disrupted late 2024, old logs still circulate |
| Meta Stealer | Windows | Sold as a RedLine derivative | Same channels as RedLine | Disrupted late 2024 |
| Raccoon | Windows | MaaS | Cracked software, malspam | Shut down 2022, v2 returned |
| Rhadamanthys | Windows | MaaS | ClickFix, malvertising | Disrupted Nov 2025, trickle of activity |
| RisePro | Windows | Sold through log markets | Pay-per-install loaders | Active, lower profile |
| Atomic Stealer (AMOS) | macOS | Subscription MaaS | Fake software, malvertising, terminal-paste lures | Active |
| Agent Tesla | Windows | MaaS and cracked builders | Phishing attachments | Active, long-running |
| FormBook / XLoader | Windows, macOS | MaaS | Phishing attachments | Active, rebranded as XLoader |
| Snake Keylogger | Windows | Sold and cracked builders | Phishing attachments | Active |
| Remcos RAT | Windows | Commercial tool, widely abused | Phishing attachments | Active |
| AsyncRAT | Windows | Open source | Phishing attachments | Active, related VenomRAT disrupted Nov 2025 |
Lumma Stealer (LummaC2)
What Is Lumma Malware?
Lumma malware is a Windows infostealer sold as Malware-as-a-Service. It steals logins, passwords, credit cards, and cryptocurrency wallet data from an infected computer, and can also act as a backdoor for dropping further Malware such as ransomware. Its reach was large: the FBI identified at least 1.7 million instances of LummaC2 being used to steal this kind of information. Lumma recovered after its 2025 takedown but is no longer the dominant family.
Lumma vs. LummaC2 vs. “Luma / Lamma”
Lumma Stealer, Lumma malware, and LummaC2 are the same family. The Department of Justice refers to it as the LummaC2 information-stealing malware service, and MITRE ATT&CK tracks it as Lumma Stealer, software S1213. “Luma” and “Lamma” are common misspellings of the same name, not separate families. The bare word “Lumma” also matches unrelated brands, so pair it with “stealer” or “malware” when searching for threat intelligence.
How Lumma Spreads (Fake CAPTCHA, mshta, PowerShell)
Affiliates who rent Lumma distribute it through fake CAPTCHA pages, malvertising, GitHub releases, game mods, and spearphishing. The most successful campaigns use the fake CAPTCHA, a ClickFix lure. The page tells the victim to open the Windows Run window, paste the clipboard contents, and press Enter, which executes a Base64-encoded PowerShell command. A common variant has the pasted command launch mshta.exe, which runs a VBScript that starts PowerShell, downloads a loader, and decrypts and injects Lumma into memory. Because the victim runs the command themselves, no exploit is involved, and many endpoint controls never fire. Microsoft has also documented compromised websites using EtherHiding and ClickFix to present the fake CAPTCHA.
C2 Infrastructure and Stealer Logs
Lumma runs on an affiliate model. Customers log into a panel where they can build the malware binary and manage C2 communications and the stolen information. Infected devices send stolen data by HTTPS POST to rotating C2 servers. As a fallback, Lumma used Telegram channels and Steam profiles as part of its backup communication network. Each infection produces a log, a bundle of credentials, cookies, and wallet data that gets sold. Our infostealer malware guide explains how logs are created and sold. After the 2025 takedown, C2 hosting shifted from Cloudflare to the Russian provider Selectel.
Persistence, MITRE Mapping and IOCs
Lumma persistence is optional. Some builds set registry Run keys or scheduled tasks, but many campaigns skip persistence because the first execution already completes the theft. Hash and domain indicators rotate quickly, so behavioral indicators are more durable. Watch for new RunMRU registry entries containing PowerShell, mshta, or encoded command syntax. Some samples use the User-Agent “TeslaBrowser/5.5”, though not all do.
| MITRE Technique | What Lumma Does |
|---|---|
| T1204 User Execution | Fake CAPTCHA instructs the victim to paste and run a command |
| T1059.001 PowerShell | Used for initial execution and other functions |
| T1218.005 Mshta | mshta.exe is used to execute additional content |
| T1620 Reflective Code Loading | Content is loaded directly into memory |
| T1547.001 Registry Run Keys | Optional persistence, set by the affiliate |
| T1041 Exfiltration Over C2 | Collected data leaves over existing HTTP and HTTPS channels |
The Microsoft/Europol Takedown and Aftermath
On May 13, 2025, Microsoft’s Digital Crimes Unit, working with Europol and Japan’s JC3, obtained a US court order to take down about 2,300 domains supporting Lumma. The Department of Justice separately seized five domains used as the Malware’s control panels. The operators spun up three replacement domains within days, and authorities seized those again.
Lumma came back. Vidar became the most-used infostealer on the Russian Market from November 2025 and displaced both Lumma and Rhadamanthys. An intelligence report notes that a doxxing campaign against Lumma’s developers damaged its reputation with customers. Treat Lumma’s indicators as current, because the code and the affiliate model survived.
Detection and Removal Notes
Lumma detection works best at execution time. Alert on the Windows Run dialog spawning PowerShell or mshta.exe with Base64-encoded arguments, and on PowerShell launched hidden or with encoded-command flags. Microsoft’s own detections include Trojan: PowerShell/ClickFixObfus. Where practical, restrict mshta.exe and the Run dialog for users who don’t need them.
Lumma steals on first run, so removal is only half the response. After an EDR or antivirus scan on the infected device, rotate passwords and revoke active sessions from a clean device. Stolen session cookies remain valid until they are invalidated. The full steps are in the removal section of our infostealer guide, and DeXpose’s Email Data Breach Scan shows whether the credentials have already surfaced.
RedLine Stealer
What It Is and How It Works
RedLine Stealer is a Windows infostealer, active since 2020 and sold as Malware-as-a-Service, that steals browser passwords, cookies, saved cards, crypto wallets, and system data. It is written in C# on the .NET framework. Criminal customers manage infections through a control panel, and they can be notified of new victims through Telegram. Affiliates spread it through phishing emails, malvertising, fake software downloads, and cracked software. The stolen data is converted to XML and sent to the operator’s C2 server over SOAP messages. One notable design choice is that RedLine skips logging victims in Commonwealth of Independent States countries. RedLine was once the most dominant Stealer in circulation, and together with its sibling Meta, it compromised over 64% of infected devices in 2024 before its takedown.
Operation Magnus and Breach History
Operation Magnus was the international law enforcement action that disrupted RedLine and Meta on October 28, 2024. The Dutch National Police and the FBI led it, coordinated by Europol and Eurojust, and it included agencies from the UK, Belgium, Portugal, and Australia, with support from ESET. Authorities shut down three servers in the Netherlands, seized two domains, made two arrests in Belgium, and recovered a client database. Investigators also mapped over 1,200 servers used by the Malware. The US Justice Department unsealed charges against Maxim Rudometov, who allegedly developed RedLine and administered its infrastructure. Meta is a closely related, newer stealer that shares developers and infrastructure with RedLine.
RedLine’s legacy is in the data. Flashpoint collected more than 451 million unique credentials from RedLine and Meta logs in 2024 alone, and logs harvested before the takedown are still traded and reused. The takedown also cleared space for successors such as Lumma.
IOCs, Detection and Removal
RedLine’s network signature is its C2 channel. It uses Windows Communication Foundation to send SOAP messages over net.tcp, often to a hard-coded IP address on a high, unusual port. The default WCF namespace tempuri.org appears in the traffic but should not be treated as a sole indicator. Intrusion detection rules exist for RedLine’s SOAP-over-TCP and SOAP-over-HTTP beaconing. Disabling net.tcp on workstations can block that exfiltration path.
File-based indicators are weak. The payload hash changes every time the operator builds a new sample from the panel, and the .NET payload can run in memory without touching disk. Persistence is inconsistent: some samples create a scheduled task, so the infected host keeps reporting to the C2, while others install nothing.
If you suspect infection, isolate the machine, run a full EDR or antivirus scan, and check scheduled tasks and startup entries. Then rotate credentials and revoke sessions from a clean device, because RedLine steals on first run. ESET released an Operation Magnus scanner for RedLine and Meta infections, and DeXpose’s Email Data Breach Scan shows whether the credentials have appeared in leaked logs. Full removal steps are in our infostealer malware guide.
Vidar Stealer
Arkei Lineage and Vidar 2.0
Vidar is a Windows infostealer sold as Malware-as-a-Service. It first appeared in 2018 on Russian-language underground forums as a fork of the Arkei stealer. It stayed a mid-tier family for years, until the takedowns of Lumma and Rhadamanthys let it rise to the top. On October 6, 2025, its developer, who goes by “Loadbaks”, announced Vidar 2.0, a full rewrite from C++ to C with a multithreaded engine that speeds up data theft. Version 2.0 also added a polymorphic builder that gives every sample a unique binary signature, a bypass for Chrome’s App-Bound Encryption, and stronger anti-analysis checks. Vidar is cheap, at a reported $300 for a lifetime license, and it targets browser cookies and autofill, crypto wallet extensions, cloud credentials, and Steam, Telegram, and Discord data.
Delivery Methods
Vidar affiliates use several delivery channels at once. The most common are malvertising, abused GitHub releases, spoofed installers, and ClickFix or FileFix prompts that trick users into pasting a PowerShell command into the Windows Run dialog. Researchers have documented Vidar 2.0 being spread through fake game cheats on GitHub and Reddit, in hundreds of repositories, with malicious links hidden behind images and routed through intermediary sites. Fake adult sites showing a realistic Windows Update screen have also been used to deliver stealers through ClickFix. In each case, the victim launches the Malware themselves, which is why Vidar victims are often people who believe they are installing legitimate software.
Analysis and Removal
Vidar’s loader allocates a memory region, decrypts the payload, and injects it, so the Stealer often runs without ever being saved to disk as a plain file. Once running, it applies debugger detection, timing checks, and hardware profiling before stealing. It typically collects everything in one pass, then self-destructs. Vidar also reads its backup C2 addresses from Telegram bots and Steam Community profiles (dead-drop resolvers). The traffic therefore looks like ordinary requests to legitimate services, and static hash-based IOCs go stale fast.
For detection, look for non-browser processes requesting Steam Community or Telegram pages, and for PowerShell launched from the Run dialog. Removal works like other stealers: isolate the machine, run a full EDR or antivirus scan, then rotate credentials and revoke sessions from a clean device. A clean scan doesn’t mean the data is safe, because Vidar may have already deleted itself. DeXpose’s Email Data Breach Scan shows whether the credentials have appeared in leaked logs. Detailed removal steps are in our infostealer malware guide.
StealC and StealC v2
What Is StealC?
StealC is a Windows information stealer and malware downloader that criminals have been buying since January 2023. It steals browser data, crypto wallet files, and data from gaming apps, messengers, email clients, and VPNs. It is written in C/C++, and its samples are commonly packed with the commercial protector Themida to slow analysis. It skips victims whose system language is spoken in Commonwealth of Independent States countries. StealC is often deployed together with the Amadey loader, and the two families have been seen delivering each other. Neither version of StealC sets up persistence, so it steals quickly, then deletes itself.
v2 Changes
StealC v2 was introduced in March 2025 and is a substantial upgrade on the original. Version 2 is compiled for 64-bit systems, uses a JSON-based C2 protocol, and adds RC4 encryption of network traffic in its later builds (2.1.1 onward). Its loader can now deliver MSI packages, PowerShell scripts, and executables. It also supports Chrome’s App-Bound Encryption, takes multi-monitor screenshots, and has a unified file grabber. Its server-side credential brute-forcing is new.
The larger change is on the operator side. The redesigned control panel has a built-in builder that lets criminals set payload rules by geolocation, hardware ID, or installed software. It also supports Telegram notifications. For example, an operator can trigger a follow-on payload whenever the stolen files mention a specific exchange. Version 2 drops the anti-VM checks and the third-party DLL downloads from version 1.
Fake CAPTCHA Campaigns
Fake CAPTCHA pages are one of StealC’s main delivery methods. The attack starts on a compromised website, where injected JavaScript loads a page that looks like a Cloudflare verification check. Instead of a puzzle, the page tells the visitor to press Windows Key + R, then Ctrl + V, then Enter. This runs a PowerShell command from the clipboard, which starts a multi-stage chain (PowerShell, shellcode, and a downloader) that ends with StealC. Because the victim performs the steps themselves, no download prompt or browser warning appears.
The same infrastructure is not tied to one payload. In one LevelBlue investigation, the delivery chain also served Lumma Stealer and a crypto clipboard hijacker in place of StealC on different runs. This fake CAPTCHA lure has been common in ClickFix campaigns since Proofpoint began tracking it in March 2024, with much of the activity based on an open-source phishing toolkit published on GitHub. To detect it, alert on PowerShell launched from the Run dialog and on powershell -nop commands that download a script.
For removal and credential rotation steps, see our infostealer malware guide. DeXpose’s Email Data Breach Scan can show whether credentials from an infection have surfaced in leaked logs.
Raccoon Stealer (v1 and v2)
The Arrest, Shutdown and v2 Return
Raccoon Stealer is a Malware-as-a-Service infostealer, first sold in 2019 for about $75 a week or $200 a month, that was shut down in March 2022 after its developer was arrested and then came back within months as version 2. Mark Sokolovsky, a Ukrainian national who advertised under names including “Photix” and “raccoonstealer”, was arrested in the Netherlands on March 22, 2022. The FBI and Dutch and Italian authorities took down the infrastructure behind the existing version. The operators told customers they were pausing after losing a core member, which many read as a death in the Russia-Ukraine war. Court documents later showed it was Sokolovsky’s arrest. The Justice Department said the Malware had collected about 50 million credentials. Sokolovsky was extradited to the US in February 2024 and pleaded guilty in October 2024 to conspiracy to commit computer intrusion.
Raccoon Stealer v2 came back quickly. Sekoia saw samples in the wild from May 16, 2022, and by then it was being sold on Telegram and hacking forums. Researchers also called it RecordBreaker. Version 2 was rebuilt from scratch in C/C++, and the operators rebuilt the infrastructure to go with it. In August 2023, they announced v2.3.0 and later v2.3.0.1, priced at $125 a week or $275 a month, with support for stealing from more than 60 applications. Raccoon has mostly been distributed as cracked software.
Analysis and IOCs
Raccoon v2 encrypts its strings and C2 addresses with RC4 or XOR, sometimes both, and sometimes not at all. It exits if the system locale is a Commonwealth of Independent States language, and it checks a mutex to avoid running twice. It also checks whether it is running with SYSTEM-level privileges and enumerates processes. To report in, it sends an HTTP POST to its C2 with a string containing the machine ID, the username, and a config ID, then uploads the stolen data and takes screenshots before finishing.
Indicators based on hashes or C2 domains go stale quickly, especially since operators regularly reset v2’s infrastructure. The more durable signs are behavioral: a cracked-software installer that spawns a process making an HTTP POST with the machine ID and username pattern, a locale check followed by data collection from browser profile folders, and a stealer that finishes and exits within seconds. Shodan has also indexed operators’ admin panels in the past.
If you suspect infection, follow the steps in our infostealer malware guide. Because Raccoon steals on first run, credential rotation matters more than removal, and DeXpose’s Email Data Breach Scan can show whether credentials from an infection have surfaced.
Rhadamanthys Stealer
Capabilities and Evasion
Rhadamanthys is a Malware-as-a-Service infostealer that steals login credentials, browser data, autofill information, cryptocurrency wallet data, and password-manager contents from infected Windows machines. It became a popular Lumma alternative because it kept adding capabilities. Version 0.7.0 gained an AI-based optical character recognition (OCR) tool that can capture crypto wallet seed phrases from images, such as screenshots on the victim’s machine. Campaigns using the ClickFix technique were documented delivering v0.7.0, which is why Rhadamanthys was widely seen as a likely successor to Lumma.
Evasion is a core selling point. Lumen’s Black Lotus Labs reported that more than 60% of Rhadamanthys command-and-control servers were undetected on VirusTotal, meaning blocklists built on public reputation data miss most of its infrastructure. It also grew quickly in late 2025, affecting an average of over 4,000 unique IP addresses a day in October, according to the same research.
Operation Endgame Disruption
Rhadamanthys was disrupted in November 2025 as part of Operation Endgame, an ongoing multinational campaign against infrastructure that enables ransomware and credential theft. Between November 10 and 14, authorities coordinated by Europol took down 1,025 servers and seized 20 domains linked to Rhadamanthys, the VenomRAT remote access trojan and the Elysium botnet. Police searched 11 locations in Germany, Greece, and the Netherlands, and arrested the main VenomRAT suspect in Greece on November 3. Rhadamanthys customers reported losing access to their servers, and the developer suspected German law enforcement after web panels logged German IP addresses. The Shadowserver Foundation alerted national security teams in 175 countries and more than 10,000 network owners about Rhadamanthys infections.
The takedown did not end the family. About three weeks later, its developer began rebuilding infrastructure and relaunched the site where he sells it. Most former customers, however, appear to have moved to competitors, especially Vidar, leaving a trickle of continued Rhadamanthys activity. If you were affected, credential rotation and session revocation still apply. DeXpose’s Email Data Breach Scan can show whether credentials from an infection have appeared in leaked logs, and our infostealer malware guide covers the removal steps.
RisePro Stealer
What Is RisePro?
RisePro is a Windows infostealer written in C++ that steals browser passwords, cookies, crypto wallet data, and browser extension data, and was first identified in December 2022. Flashpoint spotted it on December 13, 2022, when several sets of stolen logs appeared on the Russian Market log shop listing “risepro” as their source. It is not related to the consumer products that share the name. RisePro is sold through Telegram, and operators use a bot ID created by the Stealer to interact with infected systems and access logs through an admin panel. It targets around 36 browsers, plus browser extensions such as MetaMask and Coinbase. Researchers found strong similarities to Vidar, including shared dropped DLL dependencies, and Flashpoint described it as an apparent Vidar clone. By August 2023, Russian Market held over 2,000 logs allegedly sourced from RisePro.
Pay-per-install Delivery
RisePro is best known for being distributed by a pay-per-install (PPI) service called PrivateLoader. In a PPI model, a malware author pays a distributor to place its payload on as many machines as possible, and the distributor charges per successful install. PrivateLoader infected victims through websites hosting pirated software, cracks, and keygens, and before RisePro it mostly distributed RedLine and Raccoon. Sekoia found partial source-code overlaps between RisePro and PrivateLoader, including the same HTTP message obfuscation, string scrambling, and HTTP method and port setup, suggesting the two are closely related. It is not confirmed whether the same actors run both. Flashpoint noted that RisePro’s appearance as a PPI payload may signal its developer’s confidence in it.
Detection and IOCs
Most RisePro infections start earlier in the chain, at the loader stage, so the practical detection point is the pirated-software installer that runs PrivateLoader first. Look for cracked installers that spawn unfamiliar processes and write DLL dependencies to disk, and for stealer-style access to browser profile folders. Sekoia’s analysis noted that the version it studied did not use a dead-drop resolver, so its C2 address is fixed in the build, and hash or domain lists from public reports may match older samples but not new builds.
For specific hashes and domains, use the original Flashpoint and Sekoia reports and current threat feeds. If you suspect an infection, follow the steps in our infostealer malware guide. DeXpose’s Email Data Breach Scan can show whether credentials from an infection have appeared in leaked logs.
Meta Stealer Malware
What Is Meta Stealer? (It’s Not Related to Meta Platforms)
Meta Stealer, also written MetaStealer, is a Windows infostealer sold as Malware-as-a-Service since early 2022 that steals browser passwords, autofill data, cookies, and session information. Despite the name, it has no connection to Meta Platforms, the parent of Facebook, Instagram and WhatsApp, and the authorities involved in its takedown said so explicitly. It was sold on underground forums for a reported $125 to $150 a month or $1,000 for lifetime use, and in 2022 it took an 11% share of the infostealer market, in third place behind RedLine (56%) and Raccoon (15%). Because its sales pitch was a better RedLine, it is often searched for alongside RedLine.
RedLine Lineage
Meta Stealer is best described as a RedLine derivative that developed in parallel with RedLine, not a rebrand or a replacement. Its features, code, and control panel came from RedLine with only minor updates, and it was marketed as having a smaller build and a lower detection rate. ESET’s analysis found that Meta uses the same DNGuard and BoxedApp protection on its panel as RedLine. It also concluded that Meta doesn’t appear to be a successor to RedLine, because both continued to develop side by side. RedLine’s own license was priced similarly, at $150 a month or $900 for life. Both families were disrupted together on October 28, 2024, in Operation Magnus, the international action described in the RedLine section above. Elastic also documented a Meta Stealer sample in a campaign disguised as Roblox.
Detection and IOCs
Meta shares RedLine’s codebase, so defenders often start with RedLine detections. Some analyses have documented specific behavior: the Malware may run a PowerShell command to add Windows Defender exclusions for certain file types, letting it execute without antivirus alerts. Generated builds have been obfuscated with Confuser Core 1.6.0, and one sample’s binary description contained the text “METRO 2022 Dev”. Its logs include a “Domain Detector” feature that flags stolen logs containing target domains so that operators can find high-value victims quickly.
Hash and C2 indicators change with every build, and the infrastructure behind Meta was disrupted in 2024, so treat any published list as historical. If you suspect an infection, follow the steps in our infostealer malware guide. Because Meta steals cookies and saved logins on first run, rotate credentials and revoke sessions from a clean device. DeXpose’s Email Data Breach Scan can show whether credentials from an infection have surfaced.
macOS Stealers: Atomic (AMOS), Shamos and Others
What Is Atomic Stealer?
Atomic macOS Stealer (AMOS) is a macOS infostealer sold as Malware-as-a-Service, reportedly for $500 to $1,000 a month, that steals Keychain passwords, browser credentials, crypto wallet data, Telegram artifacts, and SSH keys. Attackers have used it since 2023, and it is the dominant Mac stealer. Sophos reported that AMOS accounted for almost 40% of its macOS protection updates in 2025, more than double any other macOS malware family. Many AMOS infections start with a fake system dialog that asks the user for their admin password, which it then uses to unlock and extract the Keychain.
Shamos is a variant of AMOS built by the cybercriminal group CrowdStrike tracks as COOKIE SPIDER. Between June and August 2025, a malvertising campaign spread Shamos through fake Mac help sites and spoofed GitHub repositories, and CrowdStrike blocked it in more than 300 customer environments. Victims were told to paste a single Terminal command, ClickFix-style, that downloaded a payload, stripped the file attributes that trigger Gatekeeper checks, and ran it. The stolen data was zipped and sent out with curl.
Fake GitHub Pages and Malicious Skills (ClawHavoc, OpenClaw)
Attackers use GitHub’s reputation as cover. In one widespread campaign, fraudulent GitHub repositories impersonated brands such as LastPass. They used SEO to push them to the top of search results, redirecting victims to a repository that installed AMOS. In February 2026, Huntress documented a campaign of fake OpenClaw installer repositories that delivered an information stealer and GhostSocks on Windows and AMOS on macOS.
The most striking case is ClawHavoc, a supply-chain attack on ClawHub, the marketplace where users of the OpenClaw AI agent install “skills”. Koi Security audited 2,857 ClawHub skills and found 341 malicious, of which 335 used fake prerequisites to install AMOS. On macOS, the skill instructed users to run a script that fetched a universal Mach-O binary consistent with Atomic Stealer; on Windows, it told them to download a ZIP from a GitHub repository. Antiy CERT later counted at least 1,184 malicious skills published historically by 12 author IDs, with the first appearing on January 27, 2026. The lesson is that AI agent skills are a new software supply chain, and installing one means trusting instructions written for the agent.
Cross-Platform Stealers on Mac
Several stealers work on both operating systems. XLoader, the successor to FormBook, is the best-known example. A macOS variant appeared in 2021 as a Java program, which rarely ran because macOS no longer ships with Java. In August 2023, SentinelOne found a native version written in C and Objective-C, disguised as an app called OfficeNote and signed with an Apple developer signature that Apple later revoked. The Mac version steals Chrome and Firefox passwords and clipboard content, and it has been advertised at a much higher price than the Windows version.
Newer families use the same social engineering that works on Windows. MacSync campaigns have used ClickFix lures with fake GitHub repositories and shared AI chat pages. AMOS has also been delivered through Google ads that lead to poisoned AI chat conversations. If you suspect a Mac infection, the recovery steps are the same as for Windows: isolate the device, rotate credentials and revoke sessions from a clean device, and treat everything in the Keychain as exposed. Our infostealer malware guide covers the steps, and DeXpose’s Email Data Breach Scan can show whether credentials have surfaced in leaked logs.
Credential-Stealing Trojans and Keylogger Families
Agent Tesla
Agent Tesla is a .NET spyware trojan and keylogger, sold as Malware-as-a-Service since at least 2014, that steals passwords from browsers, email clients, and FTP tools, and logs keystrokes, clipboard contents, and screenshots. Its builders have leaked, so almost any attacker can use it. Cofense found it accounted for about 20% to 30% of malware-based Active Threat Reports over the year it examined. Phishing emails are the main delivery method, and newer campaigns use multi-stage loaders that run entirely in memory. Agent Tesla exfiltrates over SMTP, FTP, HTTP, or Telegram, and it persists through the Startup folder and Run registry key. The practical detection point is outbound traffic: watch for SMTP connections from workstations and for traffic to api.telegram.org from non-browser processes.
Formbook and XLoader
FormBook is a Windows infostealer and keylogger, first offered for sale in February 2016, that grabs keystrokes, screenshots, and data from web forms. It injects into other processes and communicates with its C2 from a hijacked process such as explorer.exe. In December 2020, Check Point reported that FormBook affected 4% of organizations worldwide and ranked among the top three most prevalent Malware. FormBook disappeared from sale in 2018 and returned in February 2020 as XLoader, which shares the same codebase. XLoader is still sold as a service, and it ships with decoy C2 domains built into its configuration to slow analysis. Later versions embed dozens of encrypted C2 addresses (65 in version 8.1) and decrypt them only at runtime. It is delivered mainly as a phishing attachment, including PDFs with embedded links, Word and Excel files, and ZIP, RAR, ACE, or ISO archives. XLoader also has a macOS version, covered in the macOS section above.
Snake Keylogger
Snake Keylogger, also called 404 Keylogger, is a subscription-based .NET keylogger and credential Stealer first seen in November 2020. It steals credentials from more than 50 applications, including popular browsers, and it records keystrokes, screenshots, and clipboard contents. Operators commonly send phishing emails with a payment or invoice theme. Once running, it can inject into a legitimate .NET process and send data via SMTP, FTP, or Telegram, depending on its configuration. Analysts routinely find hard-coded SMTP credentials in the sample, which can help investigators trace the mailbox an operator uses to receive logs. For defenders, the three families in this section share one pattern: a phishing attachment, then quiet collection, then exfiltration over ordinary email, FTP, or chat protocols.
If you suspect an infection, follow the steps in our infostealer malware guide. Rotate credentials and revoke sessions from a clean device, and DeXpose’s Email Data Breach Scan can show whether they have appeared in leaked logs.
How These Families Compare
Pricing and MaaS Model, Data Targeted, Evasion, Law-Enforcement History
The major infostealer families sell for similar prices, steal much the same data, and differ mainly in how they evade detection and whether law enforcement has disrupted them. Most are rented by subscription, from about $100 to $250 a month for entry plans, while individual stolen logs sell for $5 to $50. Lumma’s tiers ran from $250 to $1,000 a month, with a $20,000 package that included the source code and the right to resell it.
Almost every family steals browser passwords, cookies, autofill data, and crypto wallets, so the differences below are the useful ones.
| Family | Reported Price | Distinctive Data / Capability | Evasion | Law-Enforcement History |
|---|---|---|---|---|
| Lumma | $250–$1,000/month; $20,000 with source |
Crypto wallets, 2FA tokens, loader for extra payloads | Fake CAPTCHA delivery, in-memory loaders | Disrupted May 2025 |
| RedLine | $150/month or $900 lifetime | VPN and FTP credentials, log sorter | .NET, in-memory loading | Disrupted Oct 2024 (Operation Magnus) |
| Meta | $125–$150/month or $1,000 lifetime | RedLine features, “Domain Detector” | Smaller build, marketed as lower detection | Disrupted Oct 2024 (Operation Magnus) |
| Vidar | About $300 lifetime | 2FA apps, cloud credentials, Steam, Telegram, Discord | Polymorphic builder, Chrome App-Bound Encryption bypass | None comparable reported |
| StealC | About $200/month | Unified file grabber, server-side brute-forcing | Themida packing, malware-side rules | None comparable reported |
| Raccoon | $200–$275/month | 60+ applications targeted | Locale and mutex checks | Arrest and shutdown 2022; guilty plea 2024 |
| Rhadamanthys | Not confirmed | Password managers, AI OCR for seed phrases | Most C2 servers undetected on VirusTotal | Disrupted Nov 2025 (Operation Endgame) |
| Atomic (AMOS) | $500–$1,000/month | macOS Keychain, Notes, SSH keys | Gatekeeper bypass, fake system dialogs | None reported |
| XLoader (FormBook) | About $59/month (Windows, 2023) | Keylogging, screenshots, form grabbing | Decoy C2 domains | None reported |
Prices come from vendor and press reports at different dates, so treat them as ranges. Families with the most law-enforcement history, Lumma, RedLine, and Rhadamanthys, are not necessarily the least active, which the next section explains.
What Happens After a Family Is Taken Down?
Why Takedowns Don’t End the Threat (Code Reuse, Rebrands, Successors)
Takedowns disrupt an infostealer’s infrastructure and sometimes its operators, but they rarely end the family, because the code, the customers, and the demand survive. Raccoon Stealer is the clearest proof point: its developer was arrested on March 22, 2022, and researchers saw samples of Raccoon v2 in the wild from May 16, less than two months later.
The threat comes back in three ways. Operators rebuild: after the Lumma disruption, its administrators registered new domains within days, and the family recovered in the months that followed. Malware gets rebranded or reused: FormBook returned as XLoader with the same code base, Meta Stealer was built from RedLine’s code, panel and features, and Vidar began as a fork of Arkei. Customers move to a successor: after RedLine and Meta were disrupted, Lumma rose to fill the gap, and after Lumma and Rhadamanthys were disrupted, Vidar became the most-used Stealer on the Russian Market from November 2025.
The stolen data also outlives the Malware. Flashpoint collected more than 451 million unique credentials from RedLine and Meta logs in 2024 alone, and logs harvested before a takedown continue to be traded and reused. Defenders should keep detections for disrupted families and monitor for credential exposure separately from malware removal. DeXpose’s dark web monitoring alerts you when credentials from these logs appear.
What is the most active infostealer right now?
Vidar. It has been the most-used Stealer on the Russian Market since November 2025, after the takedowns of Lumma and Rhadamanthys, and it accounted for more than 73% of infected hosts in early 2026.
Is Lumma still active after the takedown?
Yes. Lumma was disrupted in May 2025, but its operators rebuilt the infrastructure, and it recovered. It is no longer the market leader, having been overtaken by Vidar.
Is Vidar the same as Arkei?
No, but Vidar descends from Arkei. It first appeared in 2018 as a fork of the Arkei source code and has since been rewritten (Vidar 2.0 in October 2025).
Which stealers target macOS?
Atomic Stealer (AMOS) is the most prominent, along with its variant Shamos. MacSync and a macOS version of XLoader are also active.
Is Agent Tesla a stealer or a RAT?
Both, depending on the vendor. It is a .NET keylogger and credential Stealer with some remote-access features, and it is best described as a credential-stealing Trojan.


