Security News

Cybersecurity news aggregator

💀
HIGH Attacks SecurityWeek

Infostealers Turn Millions of Devices Into Credential Theft Machines

Infostealer malware is a primary threat vector, delivered via social engineering to infect endpoints and steal credentials, browser artifacts, and session data. These stolen credentials provide attackers with authorized, low-visibility access to corporate networks, fueling ransomware and other operations. The infostealer ecosystem is fluid, with over 30 known strains available via Malware-as-a-Service, and infection rates reached over 11 million devices in 2025, leading to billions of credentials circulating in illicit markets.
Read Full Article →

Identity & Access Infostealers Turn Millions of Devices Into Credential Theft Machines As attackers increasingly favor stolen credentials over exploits, infostealers have become a primary source of access for ransomware and other cybercrime operations. By Kevin Townsend | June 10, 2026 (10:00 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Hackers no longer force open the side-window when infostealers can give them a key to the front door. Infostealers have become the primary source of stolen credentials for attackers. Using these credentials is now a favored route for bad actors to access a target effectively as an invited guest. It is quicker, easier, less visible and more effective than forcing an entry. More than 11.1 million devices were infected with infostealers in 2025, reports Flashpoint. More than 3.3 billion credentials, browser artifacts, session information and other forms of identity are now circulating in illicit marketplaces. These don’t simply provide entry to a target, they often provide authorized access to valuable data undisturbed by security defenses within the target. Flashpoint has found more than 30 unique strains of infostealer (from hereon referred to as ‘stealers’). The precise number of ‘individual’ stealers is difficult (and probably meaningless) to quantify – the marketplace changes almost daily with new stealers appearing, existing ones forked, and law-enforcement shutting down or at least disrupting others. Stealers are available on the underground ecosystem, often via malware-as-a-service (MaaS) and for hire at as little as $60 per month. During 2025, the most successful stealers, in order, were Lumma, Acreed, Rhadamanthys, Vidar, and StealC. However, this can change rapidly. During the first two months of 2026, Vidar rose from fourth place to dominate, accounting for more than 73% of all infected hosts and devices. Lumma, number one in 2025, accounts for just 1.1% When attackers acquire a stealer, they must then infect a target device. This could usually be any device connected to the network he intends to raid since secrets available here would provide access to other parts of the network. The most common delivery method would be any of the standard social engineering attacks against anyone with a desktop or laptop. Success somewhere is statistically almost guaranteed. Advertisement. Scroll to continue reading. Individual stealers may have different processes and may steal different data. But however it operates and whatever it steals, it will be a subset of the following: It may first determine whether it is running in a sandbox (meaning its presence has been detected by security controls). If so, it may terminate activity immediately to avoid being flagged by enterprise defense systems. Its code may use string encryption and obfuscation to prevent detection by static analysis tools. Such decryption is decrypted in memory, making it visible only briefly. This makes it difficult for signature-based detection. The stealer starts to gather (usually while still in memory) whatever data it is designed to collect – which is basically whatever the designer feels can most easily be monetized. Credentials are the primary target, including website passwords, enterprise credentials (VPN, RDP, VNC, webmail), SaaS logins, cloud platform credentials, email accounts, password manager stores, and autofill data possibly containing stored personal information such as names, phone numbers, and email addresses. It may also steal browser cookies, active session tokens, and cloud/SaaS session artefacts. Stealers will look for any useful browser data, including installed extensions, and user agents. They may steal any cryptocurrency wallet information they can find, such as wallet seeds, and private keys whether from the browser or a desktop app; and any credit card data that can be found. Stealers also gather system metadata (OS version, hardware, IP address and more). By combining data and metadata, stealers don’t just steal identity, they also steal context. The stealer will package the data into content relevant files (known as stealer logs). It may compress and encrypt them to hide the content from enterprise DLP, and then send them to a web server controlled by the attacker. The attacker monetizes the logs; possibly by making personal use of them, but more likely by selling them to criminal groups. A common use by these groups is to use the stolen identities to gain undetected access to deliver and activate ransomware before they can be detected and blocked. There is often a direct and relatively short line between stealer infection and ransom demand. Stealers are easy to use, hard to detect or block, and rapacious in action. Most victims are unaware they are victims until they are breached by their own, but stolen, credentials. The only other visibility is threat intelligence finding the credentials being traded in illicit markets – but that visibility doesn’t prevent you being a victim, it merely confirms that you have become a victim. Related : The Credential Crisis: How Stolen Credentials Defeat Modern Security Related : Iranian Hackers Likely Used Malware-Stolen Credentials in Stryker Breach Related : The Blast Radius Problem: Stolen Credentials Are Weaponizing Agentic AI Related : Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications Will AI Kill the Bug Bounty Industry? OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds Offroad Emerges From Stealth With $7 Million to Tackle Enterprise Identity Risk Security of 100 AI Agents Tested and Ranked – What You Need to Know Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks Latest News Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks Alert Fatigue Is Becoming a Security Threat of Its Own CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month Hackers Exploit Langflow Vulnerability for Remote Code Execution Siemens Says Desigo CC Files Flagged as Malware by Security Engines FBI Seizes 13 Websites That Officials Say Were Used by China to Target and Recruit US Workers Splunk, Palo Alto Networks Patch Severe Vulnerabilities Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: How Modern Breaches Bypass MFA and Evade Detection June 17, 2026 Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes. Register Webinar: Modern Exposure Validation in the AI Era June 24, 2026 AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program. Register People on the Move Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView. Chaim Mazal has been named Chief Information Security Officer at GitLab. iCOUNTER has appointed Joel Molinoff as Chief Operating Officer (COO). More People On The Move Expert Insights After AI Reaches Production: 12 Ways Security Teams Can Take Control Security teams need more than visibility into AI applications, they need a repeatable framework for monitoring, investigating, and defending them in production. (Joshua Goldfarb) Everybody Is Vibe Coding But Nobody Told the Security Team AI-driven development is not something organizations can or should block. But it must be governed. (Danelle Au) The Zero-Knowledge Threat Actor and the End of Responsible Disclosure AI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code. (Etay Maor) Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email

Share this article