216.73.217.22

December 2025 Infostealer Trend Report

· Published 16/01/2026 20:33 · Modified 19/01/2026 09:29

Export JSON

Essential information

Published
16/01/2026 20:33
Modified
19/01/2026 09:29
Tags
2026-01-16 acrstealer cryptocurrency theft dll sideloading infostealer lummac2 pyagent python abuse seo poisoning stealc tor toragent
Related entities
9 observables, 9 techniques (mitre), 5 malware, 3 others

Description

This analysis examines malware trends during December 2025, focusing on distribution methods, volume, and disguising techniques. Key findings include the prevalence of , , and Infostealers, with malware primarily distributed through and compromised legitimate websites. The report highlights two significant trends: the abuse of Python scripts for malware distribution and the emergence of cryptocurrency-stealing malware using . Distribution methods evolved from direct blog posts to leveraging legitimate websites and forums. The analysis also notes a shift in malware execution methods, with 65.8% distributed as EXE files and 34.2% using techniques. The report emphasizes the importance of vigilance against these evolving threats and provides detailed insights into the malware's behavior and infrastructure.

External references