Devdiscourse User Behavior Drives 35% of Infostealer Infections, Kaspersky Reports
Article Content
- •35% of infostealer infections start from files run directly from temporary folders.
- •Infostealer infections surged by 59% in 2025, indicating a growing threat.
- •Users are often tricked into running malicious files disguised as legitimate software.
Kaspersky Digital Footprint Intelligence's recent study reveals that over one-third of infostealer infections originate from users executing files directly from temporary browser folders. An analysis of 5 million infostealer log files from the dark web in 2025 indicates that 35% of infections occurred from the Windows temporary directory, C:\Users\AppData\Local\Temp\. Additionally, 32% of cases involved the Microsoft .NET Framework directory, often linked to advanced malware techniques. The research highlights risky user behaviors, such as downloading software from untrusted sources and disabling security software before running files. Infostealer infections surged by 59% year-over-year in 2025, showing a significant increase in credential theft. Attackers often disguise malicious files as legitimate software installers or game modifications. Kaspersky advises users to download software only from trusted sources and keep security measures enabled.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Lumma in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Infostealer Malware Hijacks Claude Sessions, Drains User Accounts Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic…