User Behavior Drives 35% of Infostealer Infections, Kaspersky Reports

User Behavior Drives 35% of Infostealer Infections, Kaspersky Reports

First seen 17 Jun 2026, 18:13 UTC KasperskyDevdiscourseBusinessghana 96% similarity 51.9

Article Content

Browse articles
ThreatCluster

Kaspersky Digital Footprint Intelligence's recent study reveals that over one-third of infostealer infections originate from users executing files directly from temporary browser folders. An analysis of 5 million infostealer log files from the dark web in 2025 indicates that 35% of infections occurred from the Windows temporary directory, C:\Users\AppData\Local\Temp\. Additionally, 32% of cases involved the Microsoft .NET Framework directory, often linked to advanced malware techniques. The research highlights risky user behaviors, such as downloading software from untrusted sources and disabling security software before running files. Infostealer infections surged by 59% year-over-year in 2025, showing a significant increase in credential theft. Attackers often disguise malicious files as legitimate software installers or game modifications. Kaspersky advises users to download software only from trusted sources and keep security measures enabled.

Key Points: • 35% of infostealer infections start from files run directly from temporary folders. • Infostealer infections surged by 59% in 2025, indicating a growing threat. • Users are often tricked into running malicious files disguised as legitimate software.

ThreatCluster AI How this analysis works

Timeline

2025-01-01
Analysis of 5 million infostealer log files
Kaspersky analyzed infostealer logs from the dark web, revealing user behavior as a major infection vector.
Kaspersky
2025-01-01
Infostealer infections rise by 59%
Kaspersky reported a significant increase in infostealer infections compared to the previous year, attributed to user behavior.
Kaspersky
2026-06-15
Kaspersky publishes findings on infostealer infections
Kaspersky released a report detailing how user actions lead to infostealer infections, emphasizing the need for better security practices.
Kaspersky
2026-06-17
Businessghana reports on Kaspersky's findings
Businessghana published an article summarizing Kaspersky's research on infostealer infections and user behavior.
Businessghana
2026-06-17
Devdiscourse covers Kaspersky's research
Devdiscourse reported on Kaspersky's findings, highlighting the role of user actions in infostealer infections.
Devdiscourse

Community

Browse all →

Tracked Entities in This Story