August 2026 Infostealer Trend Report
Content
This report summarizes the distribution channels, number of Infostealers, number of detections, and companies disguised as targets by new Infostealers collected during the month of August 2026. It is based on data from AhnLab SEcurity intelligence Center (ASEC), AhnLab product diagnostic logs, automated data collection systems, email honeypot systems, and automated C2 analysis systems.
Purpose and Scope
This report was prepared to track trends in the number of infostealers, camouflage techniques, and distribution methods. It includes cases involving disguising as cracks and keygens, email distribution, and exploitation of posts on legitimate websites; statistics on disguised companies were extracted based on version and certificate information.
Key Statistics
- In crack-disguised distribution, Remus, Vidar, LummaC2, and ACRStealer were distributed. SEO poisoning, aimed at achieving top search engine rankings, was used, and file-hosting services, cloud storage platforms, Mega, and Mediafire were identified as the primary distribution sites.
- Statistics on companies disguised by new malware in August included Blue Ridge Solutions, Oleg N. Scherbakov, Microsoft Corporation, Frost Union Networks, and Cedar Stone Collective. Cases disguised as Microsoft Corporation were the most common.
- By execution type, EXE files accounted for approximately 97.3%, While DLL side-loading accounted for approximately 2.7%. Malicious DLLs used in DLL side-loading included python37.Dll, python36.Dll, Lucene.Net.Dll, OLEACC.Dll, msado15.Dll, and Microsoft.Data.Edm.Dll.
- Distribution exploiting Renpy (a Python-based open-source game development tool) was identified. Inside a ZIP file, setup.Exe and setup.Py were linked to execute malicious scripts sequentially, ultimately launching ACRStealer.
- In email distributing Infostealer cases, the Formbook infostealer—disguised as an email notifying recipients of Turkish bank account transaction statements—and the AgentTesla infostealer—disguised as a request for new business and quotes from an Indian plumbing company—were identified. AgentTesla used SMTP to transmit the stolen information.
- According to August infostealer statistics, Remus was the most frequently detected, while LummaC2, Vidar, ACRStealer, and others were actively distributed.
Conclusion
Infostealer threat groups are expanding their distribution to businesses and individual users through various methods, such as disguising themselves as cracked software, exploiting posts on legitimate websites, and luring users with email attachments. Since stolen information can be traded on the dark web or used for secondary attacks, it is essential to be cautious of untrusted links and Attachments, avoid using illegal software, enable two-factor authentication (2FA), and keep security software up to date.