Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
  • Reviews
    • Best antivirus software for 2026: independent picks from Ransomnews
    • Best ransomware-resistant backup for 2026: cloud, hybrid, and immutable picks reviewed
    • Best ransomware protection for business 2026: ESET PROTECT and 5 alternatives reviewed
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
  • Reviews
    • Best antivirus software for 2026: independent picks from Ransomnews
    • Best ransomware-resistant backup for 2026: cloud, hybrid, and immutable picks reviewed
    • Best ransomware protection for business 2026: ESET PROTECT and 5 alternatives reviewed
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Stealer Logs

Lumma vs RedLine vs Vidar in 2026: market share by infections

Ransomnews Research TeamBy Ransomnews Research TeamMay 3, 2026No Comments3 Mins Read46 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Three stylised malware vial icons with abstract emblems and bar charts showing relative market share
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

The infostealer market has consolidated around a small number of dominant families. The Operation Magnus takedowns in late 2024 disrupted RedLine and Meta significantly, but the demand for stealer logs didn’t go anywhere, it shifted to whichever families were ready to absorb the volume. Here’s the 2026 comparative picture across the three families that matter most.

Lumma, the post-takedown leader

Lumma (also known as LummaC2) emerged in 2022 and steadily grew its operator base, but the 2024-2025 RedLine disruption is what put it at the top of the leaderboard. Lumma’s distribution model is the standard malware-as-a-service: $250-$1,000 per month for builder access, with tiered features including DLL-loading, additional plugin support, and victim-data filtering tools.

What it steals: passwords from major browsers, browser cookies (essential for session-takeover attacks), cryptocurrency wallets, password manager databases, Discord and Telegram tokens, FTP credentials, autofill data. The combination is exhaustive enough to enable downstream account takeovers across most of a victim’s digital life.

Distribution remains opportunistic, fake software cracks, compromised installers, malicious search-engine ads, malvertising on YouTube. Telegram-distributed phishing pages with “verify you’re human” CAPTCHA tricks that paste PowerShell into the user’s clipboard remain a major channel.

RedLine, diminished but not gone

The October 2024 Operation Magnus takedown disrupted RedLine’s command-and-control infrastructure and indicted alleged operators. RedLine’s market share dropped sharply in late 2024 and early 2025. By mid-2026, residual RedLine activity has stabilised at roughly half its pre-takedown volume, with operators having migrated to alternate infrastructure and rebranded variants.

The takedown demonstrated something important about the stealer market: it can be disrupted, the disruption is meaningful, but the demand simply migrates. Operators who used RedLine moved to Lumma or Stealc within weeks. The total volume of fresh stealer logs hitting the market in mid-2026 is roughly comparable to pre-takedown levels.

Vidar, the survivor

Vidar has been around since 2018, weathering multiple disruption attempts and adapting through the years. It’s not the largest family by volume in 2026 but it has the most consistent multi-year track record. The codebase has spawned several derivatives (Mars Stealer, Eternity, Stealc) that share lineage and continue to be actively maintained.

Vidar’s distinguishing trait is operational maturity. The operators have been doing this for years; the malware has weathered multiple Windows defender updates; the infrastructure is rotated regularly. For affiliates who prioritise stability over cutting-edge features, Vidar remains a default.

Market share, best-effort estimates

Public estimates vary, but a reasonable consensus from multiple research feeds: Lumma sits at roughly 40-50% of fresh stealer-log volume in 2026, Stealc and successors at 15-20%, Vidar and family at 10-15%, RedLine and remnants at 5-10%, with the long tail of smaller families covering the remainder. The numbers are approximate; the relative ordering is consistent across most observers.

Defender implications

Family-specific signatures matter less than detection of the behaviours these families share: clipboard hijacking attempts, browser cookie file access by non-browser processes, large outbound POSTs to recently-registered domains, and the distinctive “verify you’re human” PowerShell-paste pattern in user help-desk tickets.

The single highest-impact defensive control across all stealer families remains user-side education: don’t paste anything into PowerShell that you didn’t write yourself, don’t run “verification” scripts from any website, and treat free pirated software as the malware-distribution channel that it actually is. Technical controls help. The behaviour change closes the gap.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleThe new mid-tier RaaS contenders: Qilin, Medusa, Embargo
Next Article How session-cookie theft replaced password theft in 2026
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

LockBit, 2 years after Operation Cronos: where are they now?

May 11, 2026

MFA bypass via cookie theft: the #1 breach vector of 2026

May 11, 2026

Ransomware attribution 2026: TTPs, notes, fingerprints

May 10, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Reviews
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Affiliate Disclosure
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.