🚀 CloudSEK has raised $19M Series B1 Round – Powering the Future of Predictive Cybersecurity
CloudSEK Logo
August 14, 2025

The Anatomy of an Attack: Pakistan Based Infostealer Delivery Network Exposed

CloudSEK’s TRIAD uncovered a Pakistan-based infostealer distribution network run through PPI schemes InstallBank and SpaxMedia/Installstera. Using SEO-poisoned warez sites and forum spam, the group delivered Lumma, Meta, and AMOS stealers, amassing 449M+ clicks, 1.88M+ installs, and $4.67M in revenue. Leaked stealer logs exposed operators, infrastructure, and financial records, revealing a family-linked operation targeting global piracy seekers via thousands of domains over five years.

Authors & Contributors

Pavan Karthick M
Threat Intelligence Researcher at CloudSEK
Vikas Kundu
Nivya Ravi
Downloadable Report

Download the Report

Download the report by clicking below.
The Download will start immediately.

Join our newsletter

Sign up so that you don't miss any updates from us
‍

The Anatomy of an Attack: Pakistan Based Infostealer Delivery Network Exposed

CloudSEK’s TRIAD uncovered a Pakistan-based infostealer distribution network run through PPI schemes InstallBank and SpaxMedia/Installstera. Using SEO-poisoned warez sites and forum spam, the group delivered Lumma, Meta, and AMOS stealers, amassing 449M+ clicks, 1.88M+ installs, and $4.67M in revenue. Leaked stealer logs exposed operators, infrastructure, and financial records, revealing a family-linked operation targeting global piracy seekers via thousands of domains over five years.

This is some text inside of a div block.

The Anatomy of an Attack: Pakistan Based Infostealer Delivery Network Exposed

August 14, 2025
This is some text inside of a div block.
min

CloudSEK’s TRIAD uncovered a Pakistan-based infostealer distribution network run through PPI schemes InstallBank and SpaxMedia/Installstera. Using SEO-poisoned warez sites and forum spam, the group delivered Lumma, Meta, and AMOS stealers, amassing 449M+ clicks, 1.88M+ installs, and $4.67M in revenue. Leaked stealer logs exposed operators, infrastructure, and financial records, revealing a family-linked operation targeting global piracy seekers via thousands of domains over five years.

Pavan Karthick M
Threat Intelligence Researcher at CloudSEK
Vikas Kundu
Nivya Ravi

Fill Details to Download

Thank You!

Your whitepaper is now downloading...
Oops! Something went wrong while submitting the form.