Devdiscourse
User Behavior Drives 35% of Infostealer Infections, Kaspersky Reports
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Kaspersky Digital Footprint Intelligence's recent study reveals that over one-third of infostealer infections originate from users executing files directly from temporary browser folders. An analysis of 5 million infostealer log files from the dark web in 2025 indicates that 35% of infections occurred from the Windows temporary directory, C:\Users\AppData\Local\Temp\. Additionally, 32% of cases involved the Microsoft .NET Framework directory, often linked to advanced malware techniques. The research highlights risky user behaviors, such as downloading software from untrusted sources and disabling security software before running files. Infostealer infections surged by 59% year-over-year in 2025, showing a significant increase in credential theft. Attackers often disguise malicious files as legitimate software installers or game modifications. Kaspersky advises users to download software only from trusted sources and keep security measures enabled.
Key Points: • 35% of infostealer infections start from files run directly from temporary folders. • Infostealer infections surged by 59% in 2025, indicating a growing threat. • Users are often tricked into running malicious files disguised as legitimate software.