August 2026 Infostealer Trend Report

Summary
AhnLab's August 2026 report documents infostealer distribution through cracked-software lures, SEO poisoning, file-hosting and cloud platforms, legitimate website posts, and email attachments. Remus was the most frequently detected infostealer; LummaC2, Vidar, ACRStealer, Formbook, and AgentTesla were also observed. The report includes five MD5 hashes and one suspicious FQDN.
Key points
- Crack-disguised distribution delivered Remus, Vidar, LummaC2, and ACRStealer, using SEO poisoning and hosting services including Mega and Mediafire.
- Remus was the most frequently detected infostealer in August; LummaC2, Vidar, ACRStealer, and others were also actively distributed.
- Malware was commonly disguised using company names, with Microsoft Corporation impersonation reported as the most common; listed disguises also included Blue Ridge Solutions, Oleg N. Scherbakov, Frost Union Networks, and Cedar Stone Collective.
- EXE files represented approximately 97.3% of observed execution types, while DLL side-loading represented approximately 2.7%; several DLL names were abused for side-loading.
- A Renpy-related campaign used a ZIP archive containing setup.Exe and setup.Py to sequentially execute malicious scripts and ultimately launch ACRStealer.
- Email campaigns delivered Formbook disguised as Turkish bank transaction statements and AgentTesla disguised as a business/quote request from an Indian plumbing company. AgentTesla used SMTP to transmit stolen information.
- AhnLab advises avoiding untrusted links and attachments and illegal software, enabling 2FA, and keeping security software updated.
Attack Vectors
- Cracked-software and keygen lures
- SEO poisoning
- File-hosting and cloud-storage distribution
- Posts on legitimate websites
- Email attachments
- DLL side-loading
- ZIP archive containing setup.Exe and setup.Py
Defensive Notes
- Be cautious of untrusted links and attachments.
- Avoid using illegal software.
- Enable two-factor authentication (2FA).
- Keep security software up to date.
Tags
Threat ResearchInfostealerCredential TheftSEO PoisoningMalicious AttachmentsDLL Side-LoadingBrand ImpersonationData Exfiltration
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | www[.]lorvag[.]xyz | FQDN indicator listed by the report. |
| MD5 | 015eab9d9dfbb6479f6001b0ec5d5f7c | MD5 indicator listed by the report. |
| MD5 | 01751fdcd020df3de36c18b2c65e319c | MD5 indicator listed by the report. |
| MD5 | 01b0c7fb95f3bd473afc02c295b6accc | MD5 indicator listed by the report. |
| MD5 | 01cd5d41e875224867c385ae931b7b4e | MD5 indicator listed by the report. |
| MD5 | 01dfd32fa42c976b09bad618a84ebc67 | MD5 indicator listed by the report. |