AhnLab Reports August 2026 Infostealer Trends, Including Remus, Vidar and LummaC2

Summary
AhnLab’s August 2026 report tracks infostealer distribution and detections, finding cracked-software lures, SEO poisoning, malicious email attachments and Ren’Py-based delivery; Remus was most frequently detected.
Key points
- The report draws on ASEC intelligence, AhnLab product diagnostic logs, automated collection, email honeypots, and automated command-and-control analysis.
- Crack- and keygen-disguised malware included Remus, Vidar, LummaC2, and ACRStealer; distribution used SEO poisoning and file-hosting or cloud-storage services.
- About 97.3% of observed malware used EXE files, while 2.7% used DLL side-loading.
- A Ren’Py-related ZIP delivery chain used setup.Exe and setup.Py to run scripts that ultimately launched ACRStealer.
- Email lures delivered Formbook disguised as a Turkish bank statement notice and AgentTesla as a plumbing-company business inquiry; AgentTesla sent stolen data via SMTP.
- Remus was the most frequently detected infostealer; LummaC2, Vidar, and ACRStealer were also actively distributed.
- AhnLab advises avoiding untrusted links and attachments and pirated software, enabling two-factor authentication, and keeping security software up to date.
Article Details
- Publisher
- AhnLab SEcurity intelligence Center (ASEC)
- Report Period
- 2026-08-01 to 2026-08-31
- Scope
- Infostealer distribution, detections, execution methods, and company impersonation, based on ASEC data, AhnLab diagnostic logs, automated collection, email honeypots, and automated C2 analysis.
- Key Statistics
- EXE files accounted for approximately 97.3% of execution types in the August 2026 infostealer statistics.
- DLL side-loading accounted for approximately 2.7% of execution types in the August 2026 infostealer statistics.
- Recommendations
- Exercise caution with untrusted links and attachments.
- Avoid using illegal software.
- Enable two-factor authentication (2FA).
- Keep security software up to date.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | www[.]lorvag[.]xyz | Threat-infrastructure FQDN listed among the report's infostealer indicators; its specific role is not disclosed. |
| MD5 | 015eab9d9dfbb6479f6001b0ec5d5f7c | Malware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed. |
| MD5 | 01751fdcd020df3de36c18b2c65e319c | Malware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed. |
| MD5 | 01b0c7fb95f3bd473afc02c295b6accc | Malware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed. |
| MD5 | 01cd5d41e875224867c385ae931b7b4e | Malware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed. |
| MD5 | 01dfd32fa42c976b09bad618a84ebc67 | Malware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed. |
MITRE ATT&CK
T1036 · MasqueradingInfostealers masqueraded as cracked software and used company identities in version and certificate information.T1059.006 · PythonRenpy-based distribution linked setup.Exe and setup.Py to execute malicious scripts sequentially and ultimately launch ACRStealer.T1566.001 · Spearphishing AttachmentInfostealers were distributed through email attachments disguised as bank transaction statements and business quotation requests.T1574.002 · DLL Side-LoadingInfostealers were executed through DLL side-loading using malicious DLLs.
Malware
ACRStealerIn crack-disguised distribution, Remus, Vidar, LummaC2, and ACRStealer were distributed.AgentTeslaas an email notifying recipients of Turkish bank account transaction statements—and the AgentTesla infostealer—disguised as a request for new business and quotes from an Indian plumbing company—wereFormBookIn email distributing Infostealer cases, the Formbook infostealer—disguised as an email notifying recipients of Turkish bank account transaction statements—and the AgentTesla infostealer—disguised as a request for newLummaC2In crack-disguised distribution, Remus, Vidar, LummaC2, and ACRStealer were distributed.RemusIn crack-disguised distribution, Remus, Vidar, LummaC2, and ACRStealer were distributed.VidarIn crack-disguised distribution, Remus, Vidar, LummaC2, and ACRStealer were distributed.