Skip to content
User Behavior Drives 35% of Infostealer Infections, Kaspersky Reports

User Behavior Drives 35% of Infostealer Infections, Kaspersky Reports

First seen 17 Jun 2026, 18:13 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 17:56 UTC
  • 35% of infostealer infections start from files run directly from temporary folders.
  • Infostealer infections surged by 59% in 2025, indicating a growing threat.
  • Users are often tricked into running malicious files disguised as legitimate software.

Kaspersky Digital Footprint Intelligence's recent study reveals that over one-third of infostealer infections originate from users executing files directly from temporary browser folders. An analysis of 5 million infostealer log files from the dark web in 2025 indicates that 35% of infections occurred from the Windows temporary directory, C:\Users\AppData\Local\Temp\. Additionally, 32% of cases involved the Microsoft .NET Framework directory, often linked to advanced malware techniques. The research highlights risky user behaviors, such as downloading software from untrusted sources and disabling security software before running files. Infostealer infections surged by 59% year-over-year in 2025, showing a significant increase in credential theft. Attackers often disguise malicious files as legitimate software installers or game modifications. Kaspersky advises users to download software only from trusted sources and keep security measures enabled.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2025-01-01
Analysis of 5 million infostealer log files
Kaspersky analyzed infostealer logs from the dark web, revealing user behavior as a major infection vector.
Kaspersky
2025-01-01
Infostealer infections rise by 59%
Kaspersky reported a significant increase in infostealer infections compared to the previous year, attributed to user behavior.
Kaspersky
2026-06-15
Kaspersky publishes findings on infostealer infections
Kaspersky released a report detailing how user actions lead to infostealer infections, emphasizing the need for better security practices.
Kaspersky
2026-06-17
Businessghana reports on Kaspersky's findings
Businessghana published an article summarizing Kaspersky's research on infostealer infections and user behavior.
Businessghana
2026-06-17
Devdiscourse covers Kaspersky's research
Devdiscourse reported on Kaspersky's findings, highlighting the role of user actions in infostealer infections.
Devdiscourse

More articles in this cluster (4)

Following this threat?

Track Lumma in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed