Malware Reloaded: New Players, Old Tactics, Bigger Threats
Summary
- LummaC2 led the malware-as-a-service infostealer market since early 2023, valued for its ease of use, broad capabilities, and appeal to low-skilled actors. Its takedown in May 2025 by international law enforcement disrupted over 2,300 domains, creating a vacuum now being filled by emerging malware platforms with similar or expanded capabilities.
- The post-LummaC2 malware ecosystem remains active and diverse, with both traditional stealers and multifunctional toolkits gaining ground.
- Aura, MonsterV2, and XFiles have emerged as the most prominent contenders to replace LummaC2, offering well-developed, actively maintained malware platforms that combine infostealing with broader spyware and remote access capabilities. All three demonstrate strong community engagement, regular technical updates, and flexible pricing models tailored to different threat actor profiles. Aura stands out for its user-friendly panel and fast development cycle, MonsterV2 for its modular botnet-like design and HVNC features, and XFiles for its mature spyware suite and professional support.
- The malware ecosystem is showing a shift toward multifunctional toolkits that combine credential theft with persistent remote access (e.g., HVNC, RAT), enabling attackers to simulate genuine user activity and bypass advanced anti-fraud systems. This trend — exemplified by tools such as MonsterV2 and XFiles — reflects a return to modular botnet-style operations, where full control of the victim’s machine is desired by cybercriminals in order to bypass security and fraud detection controls. If this trajectory continues, defenders will need to move beyond stealer-focused detection and address threats involving real-time interaction with infected devices.
Introduction
Since the beginning of 2023, LummaC2 dominated the malware-as-a-service (MaaS1) infostealer2 market. Its popularity stemmed from a highly accessible platform offering broad data exfiltration capabilities, easy deployment, and a slick, user-friendly panel — making it attractive even to low-skilled actors. In May 2025, however, LummaC2’s operations were severely disrupted by a global law enforcement takedown led by the U.S. Department of Justice, Microsoft, Europol, and other partners. Over 2,300 domains were seized, and its command-and-control infrastructure was dismantled.3 While some indicators suggest a partial return or imitation attempts, it remains unclear whether LummaC2 will regain its former scale. In light of this uncertainty, we examined the current malware ecosystem to identify which projects — particularly those offering infostealing capabilities and broader remote access or control features — may fill the vacuum left by Lumma.
Overview of the Current Malware Ecosystem
The ecosystem for credential theft and post-compromise malware remains highly active and fragmented. Despite initial expectations of disruption following the LummaC2 takedown, several other malware platforms have gained traction in Dark Web markets, including both classic infostealers and broader multifunctional toolkits. These offerings typically operate under a MaaS model, providing malware builders, web-based admin panels, and subscription pricing to lower the barrier of entry for cybercriminals.
Trust in the developer, product maturity, and community support remain key differentiators in the evolving malware landscape. To better understand which tools may gain broader adoption, we examined a selection of six emerging malware variants that have shown notable activity and Dark Web engagement in recent months. In particular, this report focuses on three prominent families — Aura, MonsterV2, and XFiles — which stand out for their sustained development and user feedback across Dark Web forums. Together, they illustrate a broader trend: the convergence of traditional infostealers with more complex spyware and modular botnet frameworks. The following analysis summarizes their core features, pricing models, and community reception, offering a snapshot of the current threat ecosystem and its most viable contenders.
Aura Stealer
Aura emerged in mid-July 2025 and has since been actively promoted across several, mostly Russian-speaking, Dark Web forums, such as XSS4, Exploit5 and BHF6. Despite being a relatively new project, it quickly attracted attention through multiple forum threads showcasing its features, pricing tiers, and ongoing development updates.

Official thread of Aura Stealer on XSS forum
Pricing
Aura is sold under a subscription-based model with multiple pricing tiers.
- The Basic plan costs $295 per month and includes standard functionality such as browser extension collection, file grabbing, Telegram bot integration, and access to a limited number of configurations and builds.
- The Advanced plan, priced at $585 per month, offers enhanced filtering, expanded build customization, support for up to five Telegram bots, and higher limits for bulk log exports.
- In August 2025, the developers also introduced a Trial plan for $165, valid for two weeks, allowing potential clients to test the product with full Basic-tier functionality.
Technical Capabilities
As described, Aura Stealer offers a broad set of capabilities, including browser credential and cookie theft, session grabbing, support for a wide range of desktop applications and crypto wallets, and a highly customizable file grabber. It allows real-time updates to collection parameters and features stealthy App-Bound cookie extraction. These functionalities are delivered via a compact, statically linked C++ build (170–250 KB packed).
Aura also claims to incorporate extensive evasion techniques to bypass detection. API calls are dynamically resolved and stored in encrypted hash tables. Anti-debugging and anti-sandboxing are always enabled and deeply integrated into the execution flow. Additional stealth features include randomized API noise (“ApiHammering”), in-memory archiving, encrypted C2 communication, and mechanisms to avoid execution in CIS countries. A captcha-based anti-leak failsafe is triggered if the build is launched unencrypted. These combined measures reflect a deliberate focus on stealth, persistence, and resistance to reverse engineering or automated security analysis.
Aura’s web-based admin panel is described as fast, customizable, and user-friendly, built using the Tabler template. It supports real-time log filtering, tag-based search, Telegram bot integration, and on-the-fly configuration updates. Users can adjust themes, manage builds, and monitor operations via dashboards with stats, maps, and charts—all designed for ease of use without requiring technical expertise.

Aura Stealer admin panel
Community Reception and Developer Reputation
Since its launch, Aura Stealer has quickly gained traction among Dark Web users, with early adopters expressing strong satisfaction with both the product and the development team. Feedback highlights not only the stealer’s rich feature set, but also the pace at which improvements are being delivered. Users noted that suggestions and bug reports were promptly addressed, often implemented within days. One reviewer specifically praised the flexible loader functionality, which allowed seamless deployment of custom payloads. Others appreciated the structured log output and the responsive support via Telegram.
In addition, our analysis of the developer’s Dark Web activity suggests a high level of technical proficiency and commitment to product development. The actor behind Aura appears well-versed in both malware engineering and community engagement — a combination that likely contributes to the stealer’s growing popularity and perceived reliability.

Satisfied customer review of Aura Stealer posted on Dark Web forum
MonsterV2 is a multifunctional modular botnet that includes infostealing capabilities as part of a broader feature set. Unlike standalone stealers, MonsterV2 positions itself as a comprehensive toolkit, combining stealer functionality with HVNC, remote access, keylogging, clipboard hijacking, a resident loader, and more. Some of these modules, particularly HVNC, are essential for bypassing modern anti-fraud mechanisms employed by financial institutions. HVNC (Hidden Virtual Network Computing) allows attackers to open an invisible remote desktop session directly on the victim’s machine, enabling them to interact with websites and applications as if they were the legitimate user, with full access to the victim’s web browser. The victim’s device must be powered on and connected to the internet for this to work, as all activity is performed locally within their environment. This tactic helps evade security measures such as device fingerprinting, IP reputation checks, and behavioral analysis by keeping all activity within the victim’s own environment.
It has been actively marketed across Russian-speaking Dark Web forums since early 2025, particularly on Exploit and XSS, and continues to receive regular development updates, feature additions, and bug fixes. Its hybrid nature and persistent update cycle make it one of the more ambitious tools in the current threat landscape.

Official thread of MonsterV2 on Exploit forum
Pricing
MonsterV2 is offered under a tiered subscription model with three main plans: Standard, Professional, and Enterprise, each providing different levels of access and capabilities.
- Standard ($300/week, $500/two weeks, $800/month): Includes access to all standard modules.
- Professional ($500/week, $800/two weeks, $1,200/month): Includes all standard modules, plus the Stealer, Loader, and API access.
- Enterprise ($850/week, $1,200/two weeks, $2,000/month): Grants access to all features of the Professional tier, and adds advanced modules such as HVNC and HCDP (details not publicly disclosed), in addition to API access.
This structured pricing allows buyers to scale their toolkit based on operational needs and budget, with short-term options (weekly/bi-weekly) for testing and campaign-specific use, as well as full monthly plans for longer-term operations.
Technical Capabilities
MonsterV2 is positioned not merely as an infostealer, but as a fully modular malware platform combining elements of a botnet, remote access trojan (RAT), HVNC (Hidden Virtual Network Computing), loader, clipper, and credential stealer.
The platform offers persistent access to infected machines through a resident daemon and includes support for launching various modules selectively across an infected botnet. Core capabilities include:
- HVNC and RAT functions for covert, real-time control of compromised systems
- Credential theft from browsers, desktop applications, and Windows Credential Manager
- Clipper functionality to hijack cryptocurrency transactions
- Loader module to deploy additional payloads to selected bots
- File and data grabbing, including support for screenshots, webcam access, and flexible file searches
- Log collection and export, with options for JSON formatting and automated syncing

MonsterV2 admin panel
MonsterV2 offers a well-integrated control structure that allows operators to manage infections with precision. Modules can be executed on selected bots or broadcast to larger groups, with options to filter, tag, and automate actions across the panel. While these capabilities are standard for tools of this class, MonsterV2 distinguishes itself through frequent updates and backend refinements—such as improved domain resolution, streamlined communication between components, and memory optimization—that enhance stability and responsiveness in live operations.

MonsterV2 victims geo distribution panel
Community Reception and Developer Reputation
MonsterV2 has received largely positive reception within the Dark Web community, particularly for its versatility and reliability. Users highlighted the toolkit’s broad functionality — from credential theft and file grabbing to HVNC and persistent loaders — noting that it “works like clockwork” across various tasks. Several buyers praised the developer’s ongoing support, with one explicitly stating the author spent two weeks helping fine-tune their setup, earning a “10 out of 10” rating.
The consistent rollout of technical updates — ranging from log filtering enhancements and geo-based segmentation to HVNC improvements — further bolstered community trust. Many users pointed to the tool’s stability and appreciated that bug fixes rarely required full rebuilds.
While some isolated negative comments surfaced — particularly around FUD capabilities and crypting — these were outweighed by a steady stream of endorsements emphasizing developer responsiveness and product maturity. The actor behind MonsterV2 maintains active forum profiles, regularly replies to questions, and pushes changelogs, reinforcing the impression of a technically capable and engaged seller.

Russian-speaking actor rates MonsterV2 ‘10 out of 10’ for functionality and stability
XFiles
Another notable project in our analysis is XFiles, a mature and actively developed spyware toolkit that first emerged on the underground scene in July 2024. Like MonsterV2, XFiles offers a modular suite of post-compromise functionalities that go well beyond credential theft. These include HVNC access, live keylogging, clipboard hijacking, file management, and detailed system reconnaissance — all delivered through a unified control panel and backed by a frequent update cadence. Now marketed under the “XFiles Spyware” label, the tool positions itself as a comprehensive solution for persistent access, monitoring, and data extraction.

Official thread of XFiles on Exploit forum
Pricing
XFiles operates on a tiered monthly subscription model, with each level offering progressively more advanced functionality:
- Premium – $200/month: Entry-level access to core stealer features, loader, team support, and bulk log management.
- Thief – $450/month: Adds manual crypting and guaranteed Microsoft Defender bypass.
- Thief+ – $1,500/month: Introduces hidden spyware modules, including HVNC, keylogger, clipper, and screen monitoring.
- Professional – $3,000/month: Includes stealth enhancements such as DLL-based SmartScreen/browser alert bypass and LNK builder.
- Enterprise – $6,000/month: Offers AV killer functionality, digitally signed payloads, and fully customized launcher builds.
This structured pricing model targets actors of varying sophistication levels and highlights XFiles’ transition into a comprehensive spyware platform.
Technical Capabilities
XFiles offers a comprehensive set of post-compromise functionalities typically associated with advanced spyware. The toolkit supports HVNC access, live keylogging, clipboard hijacking, and remote file management, as well as detailed system information gathering via the web panel. Users can browse active sessions, extract browser-stored credentials and cookies, and interact with the infected host through a customizable interface.
The product includes two builder tools — LNK Builder and HTML Builder — that help operators create custom payloads for delivery. The LNK Builder allows users to generate malicious shortcut files (“.lnk”) with various execution modes, such as running embedded scripts or downloading and executing remote files. It also features a built-in obfuscator to make detection more difficult. The HTML Builder is designed to generate payloads embedded in HTML files, which can be used in phishing pages or as part of social engineering schemes that trick victims into opening the malicious content.
Recent updates also introduced dual-monitor support for HVNC, refined file manager operations (upload/download/delete), and enhanced the log filtering experience within the admin panel. These updates reflect the developer’s continued investment in usability and functionality.
XFiles is available in both browser-based and standalone desktop versions, giving users flexibility in how they manage infections. The desktop version has been described as smoother and more responsive compared to the web panel, though both appear to be actively maintained.

XFiles admin panel
Community Reception and Developer Reputation
XFiles has cultivated a loyal user base, with numerous Dark Web forum members praising both the product’s reliability and the professionalism of its developer. Feedback highlights the software’s consistent performance across features such as HVNC, log collection, and remote access modules. Users especially appreciate the developer’s responsiveness to bug reports and feature suggestions, often noting that fixes are implemented within days. Several long-time customers emphasized their satisfaction with the support experience, describing it as attentive and technically competent.
This positive reception appears to stem in part from the developer’s visible and sustained commitment to the project. Known as LuciferXFiles, the actor maintains an active presence on major Dark Web forums, regularly posting version updates, engaging with clients, and offering discounts during promotional periods. Across multiple threads, this consistency has helped establish a reputation for credibility and ongoing support — a critical factor in the crowded and often volatile underground malware ecosystem.

Dark Web user praising XFiles performance and support
Other Notable Projects
While Aura, MonsterV2, and XFiles stand out as the most structured and mature contenders to replace LummaC2, they represent only the upper tier of a much broader and highly fragmented malware landscape. Numerous other tools — often less stable, more niche, or targeted at lower-tier users — continue to circulate in both Russian- and English-speaking Dark Web communities. The following three are just a few illustrative examples among many:
123 Stealer is a budget-oriented tool offering basic stealer functionality. With limited evasion techniques and a narrow scope (primarily Chromium-based browsers and desktop wallets), it attracts entry-level actors seeking simplicity over sophistication. Updates are sporadic, but ease of use and low pricing keep it marginally relevant.
Bee Stealer attempts to strike a balance between affordability and modularity. It features browser data theft, file grabbing, and add-on modules like keyloggers and clippers. While user feedback is mixed, the developer remains responsive and regularly issues updates — giving it some traction among mid-tier buyers.
Prysmax Stealer began as a fork of publicly available code but has since evolved into a more refined product. With support for Discord token theft, UAC bypasses, and a steadily improving user interface, Prysmax targets actors looking for a low-cost solution with semi-professional polish. Despite lingering skepticism over its origins, the developer has cultivated an active user base and continues to push frequent updates.
Conclusion
Although infostealers continue to play a significant role in the cybercriminal ecosystem — valued for their ease of deployment, rapid data extraction, and relatively low operational overhead — we are observing signs of a possible shift in actor preferences. Notably, more sophisticated threat actors appear to be gravitating toward multifunctional malware frameworks that incorporate credential theft alongside persistent remote access features. This trend does not necessarily signal a new evolution but may instead reflect a return to more traditional models of modular malware. Several years ago, credential theft was often just one component of broader botnet infrastructures. Today, we are seeing increased interest in toolkits like MonsterV2 and XFiles, which offer integrated HVNC, RAT, file management, and log streaming capabilities. These features allow operators to maintain live access to compromised devices — an increasingly valuable asset given the enhanced security and fraud detection mechanisms now used by most large institutions.
Indeed, simply possessing credentials or session tokens is often insufficient to complete account takeover. Advanced security and anti-fraud systems rely on behavioral analytics, device fingerprinting, and risk-based authentication, making full control of the victim’s environment critical to bypassing such barriers. In this context, capabilities such as HVNC are being leveraged to simulate genuine user behavior from the infected host.
In many cases, an attacker doesn’t even need to know the victim’s login credentials — users frequently store them in browsers, where they are automatically filled into login forms. As seen in the screenshot below, the attacker accesses the victim’s machine via HVNC, with all credentials conveniently displayed through the browser’s autofill function.

While it is too early to determine whether this signals a lasting pivot in the malware community, it appears that many experienced actors are now favoring tools that offer more than just credential theft. If this trend continues, defenders may need to expand their focus beyond stealers and adapt to threats that blend data exfiltration with real-time device control.
Please submit your information below to request the full research report
Don’t forget
to Visit
Our Solutions
1Malware-as-a-Service is a criminal business model where developers sell or lease ready-to-use malware and supporting services (hosting control panels customer support).
2Infostealer is a type of malware designed to steal passwords and personal data.
3https://www.justice.gov/opa/pr/justice-department-seizes-domains-behind-major-information-stealing-malware-operation
4www[.]xss[.].pro
5www[.]exploit[.]in
6www[.]bhf[.]pro
About the Author(s)
Dima Khrustalov is a manager of the Research Team at Q6 Cyber, covering global cybercriminal activities on the Dark Web and Deep Web. Dima has more than eight years experience in fighting cyber fraud and e-crime, specializing in Eastern European cyber underground.
Share