More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
More than 11.1 million devices picked up infostealer malware in 2025, and over 3.3 billion sets of credentials, browser artifacts and session tokens are now trading on underground markets. Flashpoint found more than 30 active stealer families, though that count shifts daily as new strains appear, others fork and law-enforcement disrupts operations. Stealers rent for as little as $60 a month under malware-as-a-service models, putting turnkey credential theft within reach of low-skill actors.
In 2025, the biggest players were Lumma, Acreed, Rhadamanthys, Vidar and StealC. Vidar surged in early 2026, jumping from fourth to control 73 percent of infections; Lumma, last year’s leader, fell to about 1.1 percent. Attackers distribute these tools through standard social-engineering lures—phishing emails, malicious downloads—targeting any desktop or laptop on corporate networks. Once installed, a stealer checks for sandboxes to avoid analysis, then uses encrypted and obfuscated code to slip past signature-based defenses.
From memory alone, stealers harvest everything they can monetize: saved passwords for websites and enterprise services (VPN, RDP, VNC), cloud-platform and SaaS logins, browser cookies and active session tokens. They grab autofill data, installed-extension lists, cryptocurrency wallet seeds or private keys, even credit-card info stored in browsers. System metadata—OS version, IP address and hardware details—travels with the haul, giving buyers context that helps them move laterally inside networks.
All stolen data is bundled into encrypted “stealer logs” and exfiltrated to attacker-controlled servers. Criminals then trade or sell those logs to other groups, who often use them to slip ransomware past defenses. Victims usually don’t detect anything until they see ransom demands or find their credentials for sale. Threat intel can confirm a breach by spotting credentials in markets, but that insight comes after the damage is done.
Questions about this article
No questions yet.