CryptoLek

joined 2 years ago
 

A brief look at all things infostealers for the week 20, 2025 (12.05.2025–18.05.2025). This week observed updates from LummaC2, MonsterV2 and KatzStealer infostealers. Grabbed some numbers from marketplaces and some interesting news/articles.

 

Blogged a bit about Kidflix login credentials and tried to make some basic password analysis. Originally the bulk of the post was written in the beginning of April, but I forgot and it was just sitting there in my drafts directory.

 

A brief look at all things infostealers for the week 18, 2025 (28.04.2025–04.05.2025). This week observed updates from LummaC2 and StealC infostealers. Grabbed some numbers from marketplaces and some interesting news/articles.

 

In the beginning of March 2025, user of XSS forum “plymouth” made a post in their stealer thread about the upcoming major update to the infostealer. Finally, on 30th March they posted announcement and details of the StealC V2 release. According to the user, the development of the second version took half a year, and in its essence, it is entirely new software.

[–] CryptoLek 2 points 2 months ago

I sometimes wonder if I should go "solo" consultant road of CTI. Solely for the purpose of being flexible with the family and a bit travelling and working from different parts of Europe and its borderlands (no Russia).

Or should I keep searching for a company that pays ok and doesn't mind if I work outside of my primary location (Nordics)?

4
mac.c macOS Stealer (cryptolek.info)
submitted 2 months ago by CryptoLek to c/cybersecurity
 

On 14 March 2025, a user “mentalpositive” on XSS Forum has posted a thread advertising a new MacOS infostealer. Below is the machine translation of the user’s forum post, with minor edits by me (I have copy-pasted just the intro, the rest on the blog, if interested):

spoilermac.c macOS Stealer is a stealer for devices running the macOS operating system. Works on all system versions starting from macOS Sierra (>10.12.6). Written in C, the build weight at the time of writing the topic is ~140 KB. Both architectures are supported: x64_86, ARM. Collect cookies, passwords, autofills and history from Chromium-based browsers, device information, Telegram session, desktop cryptocurrencies and cryptocurrencies, screenshot and decrypted device keychain. And the ability to change the text in modal windows when a password is requested will make your work even more pleasant!