Monday, August 3, 2026
  • About
  • Advertise
  • Careers
  • Contact
NewsTrendsKE
  • Business
    • Deals
  • OpEds
  • Sustainability
  • Women in Business
  • Lifestyle
  • Featured
  • Technology
    • Phones
  • Sports
  • World
  • Contact Us
No Result
View All Result
NewsTrendsKE
No Result
View All Result

Home » Technology » Kaspersky: 35% of infostealer infections begin with users running files directly from temporary folders

Kaspersky: 35% of infostealer infections begin with users running files directly from temporary folders

Queen Amber by Queen Amber
2 months ago
in Technology
Reading Time: 4 mins read
A A
NewsTrendsKE with APO News Updates
Share on FacebookShare on TwitterShare on WhatsApp
Kaspersky

New research by Kaspersky Digital Footprint (DFI) (www.Kaspersky.co.za) has discovered that more than one-third of infostealer infections start when users run files directly from temporary browser folders, showing that user behaviour remains a key factor behind credential theft. Just 32% of infostealer attacks use process injection and living‑off‑the‑land techniques — behaviour typical of advanced malware families. 

Also Read

Safaricom Data Privacy Mpesa

Your Phone, Your Money: Six Habits Safaricom Says You Need to Stop

31 July 2026
From left: Liu Jia, Deputy Chief Representative Officer, ICBC Africa; Florence Wanja, Head of Business and Commercial Banking, East Africa, Stanbic Bank; Guo Haiyan, Ambassador of the People’s Republic of China to Kenya; Jonathan Muga, Head of Corporate and Investment Banking, Stanbic Bank Kenya; and Mo Yongnian, Chief Financial Officer, China Road and Bridge Corporation Kenya, pose for a photograph during Stanbic Bank Kenya’s Economic Outlook and RMB Business Ecosystem China Day celebration.

Stanbic Launches Direct China Payment System for Kenyan Businesses

31 July 2026
Load More

Kaspersky DFI researchers analysed 5 million infostealer log files discovered on the dark web in 2025. These logs, which contain data stolen from compromised devices such as account credentials, browser cookies and system metadata, also revealed the original locations of malicious files on infected machines. 

The most common location was the Windows temporary directory, C:UsersAppDataLocalTemp, which accounted for approximately 35% of all observed cases. This folder is commonly used to store files downloaded from the Internet before they are explicitly saved by a user: a significant share of infections occurs when users directly launch downloaded files, without attackers relying on sophisticated evasion techniques.  

The second most common location, responsible for about 32% of cases, was C:WindowsMicrosoft.NETFramework. This path is associated with process injection and living-off-the-land techniques, in which malware abuses legitimate system processes to evade detection. Such behaviour is commonly observed in more advanced infostealer families, including Lumma (https://apo-opa.co/4efwnHn). 

The analysis indicates that infections are often linked to two risky user actions: downloading software from untrusted sources and attempting to activate software illegally. In many cases, victims follow instructions provided by threat actors and disable security software before running malicious files. According to the research, many malicious files were disguised as legitimate software installers, activators or game modifications. While game mods remain a common lure, attackers frequently adapt the same techniques to distribute virtually any type of software.  

“Infostealers surged (https://apo-opa.co/4oxo3pT) in 2025, with infections rising 59% year over year. Our analysis shows that user behaviour remains a key factor behind many of these compromises. The volume of infostealers executed from temporary download folders suggests that users often launch them immediately after downloading. In many cases, attackers do not need sophisticated techniques, they simply need to convince a user to run a file,” said Sergey Shcherbel, expert at Kaspersky Digital Footprint Intelligence.  

Beyond behavioural traits, distinct naming patterns were also observed across infostealer families. Lumma tends to favour generic installer names, .NET obfuscation and process injection. Vidar, in turn, typically appears as Bootstrapper.exe variants relying on conventional loaders. Stealc follows a mixed strategy, using both meaningful names like Licence_Version_Loader.exe and randomly generated filenames. RisePro, by contrast, stands out through recurring conventions such as MPGPH.exe and MSIUpdater.exe. 

The full report is available here (https://apo-opa.co/4xE67OE). 

To reduce the risk of infostealer infections, Kaspersky recommends businesses do the following: 

  • Adopt a comprehensive digital risk protection service that monitors organisations’ digital assets and detects threats across the surface, deep and dark web such as Kaspersky Digital Footprint Intelligence (https://DFI.Kaspersky.com/). 
  • ​Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organisation. The latest Kaspersky Threat Intelligence (https://apo-opa.co/3SML38o) provides them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner. 

To stay safe users are recommended to: 

  • Download software only from official and trusted sources, avoiding pirated software, cracks, activators and unofficial installers. 
  • Use a strong security solution on all computers and mobile devices, such as Kaspersky Premium (https://apo-opa.co/4vUrWrA). It will warn you about potential threats and prevent infection. 
  • Manage sensitive data securely: avoid storing passwords or recovery phrases in your photo gallery or notes; instead, use a dedicated, trusted password manager such as Kaspersky Password Manager (https://apo-opa.co/4vSYt0Y). 
  • Never disable antivirus or security tools to install software and exercise caution when downloading game mods, cheats or third-party utilities. 
  • Keep operating systems and applications updated, use strong, unique passwords and enable multi-factor authentication wherever possible. 

Distributed by APO Group on behalf of Kaspersky.

For further information please contact:
Nicole Allman
nicole@inkandco.co.za

Follow us:
Facebook: https://apo-opa.co/4fRBlvi
X: https://apo-opa.co/4oz3aL7
YouTube: https://apo-opa.co/4oAEvpq
Instagram: https://apo-opa.co/4oyNure
Blog: https://apo-opa.co/4vfetKK

About Kaspersky: 
Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date. Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support. Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.Kaspersky.co.za. 

Media files
Kaspersky
Download logo
Previous Post

Society of Petroleum Engineers (SPE) Africa and African Energy Chamber (AEC) Sign Strategic Agreement to Advance Technical Excellence Across Africa’s Energy Sector

Next Post

Stanbic Bank Kenya, Simba Corporation Launch 100% Asset Financing to Ease Business Cost Pressures

Related Posts

Safaricom Data Privacy Mpesa
Technology

Your Phone, Your Money: Six Habits Safaricom Says You Need to Stop

31 July 2026
From left: Liu Jia, Deputy Chief Representative Officer, ICBC Africa; Florence Wanja, Head of Business and Commercial Banking, East Africa, Stanbic Bank; Guo Haiyan, Ambassador of the People’s Republic of China to Kenya; Jonathan Muga, Head of Corporate and Investment Banking, Stanbic Bank Kenya; and Mo Yongnian, Chief Financial Officer, China Road and Bridge Corporation Kenya, pose for a photograph during Stanbic Bank Kenya’s Economic Outlook and RMB Business Ecosystem China Day celebration.
Business

Stanbic Launches Direct China Payment System for Kenyan Businesses

31 July 2026
Standard Chartered Bank
Sustainability

Standard Chartered Kenya’s sustainable finance assets rise to KSh62.5 billion

30 July 2026
Britam Connect
Health

Britam unveils a medical cover Bima ya Wafanyakazi for domestic and informal workers

29 July 2026
From left: Liu Jia, Deputy Chief Representative Officer, ICBC Africa; Florence Wanja, Head of Business and Commercial Banking, East Africa, Stanbic Bank; Guo Haiyan, Ambassador of the People’s Republic of China to Kenya; Jonathan Muga, Head of Corporate and Investment Banking, Stanbic Bank Kenya; and Mo Yongnian, Chief Financial Officer, China Road and Bridge Corporation Kenya, pose for a photograph during Stanbic Bank Kenya’s Economic Outlook and RMB Business Ecosystem China Day celebration.

Stanbic Launches Direct China Payment System for Kenyan Businesses

31 July 2026
KRA Offices

KRA Customs Revenue Hits Record KSh988.8 Billion Amid Car Import Tax Dispute

29 July 2026
Naivas Kamakis

Naivas Kamakis Now Opens at Newgate Square

17 July 2026
I&M Bank Container Banks

Abdi Mohamed’s Move to I&M Signals Battle for East Africa’s Wealthy, Affluent Clients

30 June 2026

Boyz II Men: Timeless Harmonies that Define an Era

6 June 2023
Safaricom Data Privacy Mpesa

Your Phone, Your Money: Six Habits Safaricom Says You Need to Stop

31 July 2026
NewsTrendsKE

NewsTrendsKE

A News Blog For Readers Who Want More

Follow us on social media:

  • About
  • Advertise
  • Careers
  • Contact

©2026 NewsTrendsKE.

No Result
View All Result
  • Business
    • Deals
  • OpEds
  • Sustainability
  • Women in Business
  • Lifestyle
  • Featured
  • Technology
    • Phones
  • Sports
  • World
  • Contact Us

©2026 NewsTrendsKE.

Go to mobile version