August 2026 Infostealer Trend Report

· Original article ↗

Summary

AhnLab's August 2026 report documents infostealer distribution through cracked-software lures, SEO poisoning, file-hosting and cloud platforms, legitimate website posts, and email attachments. Remus was the most frequently detected infostealer; LummaC2, Vidar, ACRStealer, Formbook, and AgentTesla were also observed. The report includes five MD5 hashes and one suspicious FQDN.

Key points

  • Crack-disguised distribution delivered Remus, Vidar, LummaC2, and ACRStealer, using SEO poisoning and hosting services including Mega and Mediafire.
  • Remus was the most frequently detected infostealer in August; LummaC2, Vidar, ACRStealer, and others were also actively distributed.
  • Malware was commonly disguised using company names, with Microsoft Corporation impersonation reported as the most common; listed disguises also included Blue Ridge Solutions, Oleg N. Scherbakov, Frost Union Networks, and Cedar Stone Collective.
  • EXE files represented approximately 97.3% of observed execution types, while DLL side-loading represented approximately 2.7%; several DLL names were abused for side-loading.
  • A Renpy-related campaign used a ZIP archive containing setup.Exe and setup.Py to sequentially execute malicious scripts and ultimately launch ACRStealer.
  • Email campaigns delivered Formbook disguised as Turkish bank transaction statements and AgentTesla disguised as a business/quote request from an Indian plumbing company. AgentTesla used SMTP to transmit stolen information.
  • AhnLab advises avoiding untrusted links and attachments and illegal software, enabling 2FA, and keeping security software updated.

Attack Vectors

  • Cracked-software and keygen lures
  • SEO poisoning
  • File-hosting and cloud-storage distribution
  • Posts on legitimate websites
  • Email attachments
  • DLL side-loading
  • ZIP archive containing setup.Exe and setup.Py

Defensive Notes

  • Be cautious of untrusted links and attachments.
  • Avoid using illegal software.
  • Enable two-factor authentication (2FA).
  • Keep security software up to date.

Tags

Threat ResearchInfostealerCredential TheftSEO PoisoningMalicious AttachmentsDLL Side-LoadingBrand ImpersonationData Exfiltration

Indicators of compromise

TypeIndicatorContext
DOMAINwww[.]lorvag[.]xyzFQDN indicator listed by the report.
MD5015eab9d9dfbb6479f6001b0ec5d5f7cMD5 indicator listed by the report.
MD501751fdcd020df3de36c18b2c65e319cMD5 indicator listed by the report.
MD501b0c7fb95f3bd473afc02c295b6acccMD5 indicator listed by the report.
MD501cd5d41e875224867c385ae931b7b4eMD5 indicator listed by the report.
MD501dfd32fa42c976b09bad618a84ebc67MD5 indicator listed by the report.

MITRE ATT&CK

Malware

Vendors

Products

Countries

Industries