AhnLab Reports August 2026 Infostealer Trends, Including Remus, Vidar and LummaC2

· Original article ↗

Summary

AhnLab’s August 2026 report tracks infostealer distribution and detections, finding cracked-software lures, SEO poisoning, malicious email attachments and Ren’Py-based delivery; Remus was most frequently detected.

Key points

  • The report draws on ASEC intelligence, AhnLab product diagnostic logs, automated collection, email honeypots, and automated command-and-control analysis.
  • Crack- and keygen-disguised malware included Remus, Vidar, LummaC2, and ACRStealer; distribution used SEO poisoning and file-hosting or cloud-storage services.
  • About 97.3% of observed malware used EXE files, while 2.7% used DLL side-loading.
  • A Ren’Py-related ZIP delivery chain used setup.Exe and setup.Py to run scripts that ultimately launched ACRStealer.
  • Email lures delivered Formbook disguised as a Turkish bank statement notice and AgentTesla as a plumbing-company business inquiry; AgentTesla sent stolen data via SMTP.
  • Remus was the most frequently detected infostealer; LummaC2, Vidar, and ACRStealer were also actively distributed.
  • AhnLab advises avoiding untrusted links and attachments and pirated software, enabling two-factor authentication, and keeping security software up to date.

Article Details

Publisher
AhnLab SEcurity intelligence Center (ASEC)
Report Period
2026-08-01 to 2026-08-31
Scope
Infostealer distribution, detections, execution methods, and company impersonation, based on ASEC data, AhnLab diagnostic logs, automated collection, email honeypots, and automated C2 analysis.
Key Statistics
  • EXE files accounted for approximately 97.3% of execution types in the August 2026 infostealer statistics.
  • DLL side-loading accounted for approximately 2.7% of execution types in the August 2026 infostealer statistics.
Recommendations
  • Exercise caution with untrusted links and attachments.
  • Avoid using illegal software.
  • Enable two-factor authentication (2FA).
  • Keep security software up to date.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEwww[.]lorvag[.]xyzThreat-infrastructure FQDN listed among the report's infostealer indicators; its specific role is not disclosed.
MD5015eab9d9dfbb6479f6001b0ec5d5f7cMalware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed.
MD501751fdcd020df3de36c18b2c65e319cMalware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed.
MD501b0c7fb95f3bd473afc02c295b6acccMalware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed.
MD501cd5d41e875224867c385ae931b7b4eMalware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed.
MD501dfd32fa42c976b09bad618a84ebc67Malware artifact hash listed in the report's infostealer indicators; family attribution is not disclosed.

MITRE ATT&CK

Malware

Vendors

Products

Related Articles