July 2026 Infostealer Trend Report
Content
This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs from AhnLab products.
Purpose and Scope
This report is designed to help track trends in the quantity of infostealer distribution, disguising techniques, and distribution methods. Various distribution methods are covered, including cracks, keygens, posts on legitimate websites, email, MSBuild (msbuild.Exe), and DLL side-loading.
Key Statistics
In July, the Remus, LummaC2, ACRStealer, and Vidar infostealers were distributed by disguising them as cracks and illegal software. The primary distribution domains were mega.Nz, s3.Us-east-1.Amazonaws.Com, and Mediafire. Microsoft Corporation was the most frequently impersonated company, followed by AnyDesk Software GmbH, AO Kaspersky Lab, openaudible.Org, and Samsung Electronics Co., Ltd.
In terms of execution types, EXE files accounted for approximately 89.6%, While DLL side-loading accounted for approximately 10.4%. The DLLs used in DLL side-loading included python37.Dll, libbrotlienc.Dll, python315.Dll, libvlc.Dll, DotNetZip.Dll, and msys-sasl2-3.Dll.
In terms of trends, numerous cases of distribution exploiting MSBuild, a Microsoft development tool, were identified. The threat actors distributed a compressed file containing Install.Exe, Install.Csproj, and a malicious DLL in the same Path. When a user runs Install.Exe, DotNetZip.Dll is executed through the tasks in Install.Csproj, after which it communicates with the C2 server to download and execute additional payloads.
In email-based distribution cases, emails disguised as messages from a UAE trading company and a pharmaceutical firm were identified. The Attachment in the first case contained MassLogger, while the Attachment in the second case contained AgentTesla. MassLogger can steal account credentials, screenshots, keylogging data, and clipboard information stored in browsers and on clients, while AgentTesla can transmit information via FTP, Telegram, and SMTP.
Conclusion
Infostealer threat groups are actively spreading to both enterprises and individual users through various distribution methods. Stolen information may be traded on the dark web or used for secondary attacks. The report emphasizes the need to be cautious of untrusted links and Attachments, avoid using cracks and keygens, exercise caution when saving account information in browsers, use file encryption to protect important documents, change passwords periodically, use two-factor authentication (2FA), and keep security software up to date.