What are examples of infostealer malware in 2025?
·
Written by Anthony Wedding
— co-founder
Short answer
Several credential stealer families are actively used in 2025, each with slightly different focus areas, delivery methods, and payloads, and most are sold as Malware-as-a-Service so they can be purchased and deployed without any technical skill. The most commonly seen families include Lumma, RedLine, Raccoon v2, Meta, RisePro, and Vidar. Each targets a similar core of browser credentials and session tokens, with some adding specializations like file grabbing or financial data extraction.
The most commonly seen families
Lumma: the most dominant infostealer in 2025, known for rapid development, modular payloads, and advanced evasion features.
RedLine: was long the number one infostealer, now overtaken by Lumma but still widely distributed. Several of its infrastructure servers were taken down during Operation Magnus, a coordinated law enforcement effort in 2024\.
Raccoon v2: recently re-emerged after a takedown, popular for its low cost and simplicity.
Meta: shares infrastructure with other loaders and is often part of multi-stage attacks.
RisePro: believed to be a fork of Lumma, with a focus on exfiltrating financial and session data.
Vidar: includes clipboard and file grabber features, sometimes deployed alongside ransomware.
Why tracking these families matters
Each family has slightly different targets and delivery methods, but they share the same underlying threat: browser-stored credentials and session tokens that can grant attackers direct access to accounts. Because most are sold as MaaS, new operators can deploy any of these families with no technical skill of their own, which keeps infection volumes high across all of them.
For a deeper technical breakdown of individual samples, Malpedia maintains a searchable index of stealer families.
