A stealer log is not merely a log file. It is a structured, compressed archive of everything a piece of stealer malware has silently harvested from an infected device usually before the victim had any idea anything was wrong, if they ever did. Unlike ransomware, which announces itself with locked screens and ransom notes, infostealer malware operates without disrupting normal device function and therefore can be difficult to detect. The infected machine keeps running. The user keeps working. Meanwhile, the malware is methodically copying credentials from every browser, extracting active session cookies, reading cryptocurrency wallet files, and sometimes even photographing the desktop — then packaging everything into a neat archive and transmitting it to an attacker-controlled server.
Each log, in the language of underground markets, represents one “bot” — one compromised device, one victim’s complete digital footprint, ready for purchase and exploitation.

The value of a stealer log to a criminal depends heavily on what it contains. Logs with bank credentials, for instance, will be more valuable than other types of credentials. However, there are a lot of other data types withing a stealer log which can be very advantageous to criminals. Logs are typically organized by data type within the archive, making it simple for buyers to locate specific categories of value. The standard contents break down into six main categories:
One particularly dangerous aspect of a stealer log infection is its attack on session persistence. When a user logs into a website and completes multi-factor authentication, the browser stores a session cookie confirming that the device has already authenticated. An attacker who imports that cookie can access the same account with no password required, and no MFA challenge triggered. Microsoft’s own documentation confirms that certain session cookies can persist until explicit logout or token expiration, potentially enabling weeks of undetected access with a single stolen log.
Sellers routinely re-package the same log multiple times — as a cheap raw dump, a premium corporate set, and a crypto-only slice — reselling the same victim data to multiple buyers. Underground market research suggests tens of billions of stolen cookies were circulating in 2025.
The infostealer malware ecosystem operates as a commercially organized, subscription-driven marketplace. Most major variants are sold as Malware-as-a-Service (MaaS), with developers offering monthly subscriptions, customer support forums, update bulletins, and affiliate programs. According to IBM X-Force’s 2025 threat intelligence report, the following families dominated dark web forum activity throughout 2024 and into 2025:

The broader pattern is consistent across every law enforcement disruption: when one major infostealer family is taken down, market share migrates to alternatives within days to weeks, or the malware is updated on new C2 servers run by other affiliates. This resilience stems from the structural nature of the ecosystem. Low development barriers, open-source code availability, and persistent criminal demand ensure that neutralizing any single actor creates an immediate commercial opportunity for others.
The underground market for stealer logs operates across several parallel channels, each serving different buyer profiles and transaction volumes. Understanding where logs are distributed is central to understanding how quickly stolen data can be weaponized after an infection.

Following the Genesis Market seizure in April 2023, SecureWorks documented a 670% increase in Russian Market activity as buyers and sellers migrated. This pattern has repeated across every major marketplace takedown: the criminal ecosystem absorbs the disruption rapidly, and within weeks, activity consolidates on surviving platforms or new entrants.

Stealer logs are usually the first step in an often more sophisticated attack. Information that can be found in logs is often used as part of other attacks, usually against organizations rather than against the individuals that were initially infected.
Initial Access Brokers (IABs) will sift through millions of logs, which they may control themselves or have purchased, looking specifically for corporate VPN credentials, SSO tokens, and domain admin access. Qualifying logs are re-packaged and sold on dark web forums for significantly higher prices.
Ransomware affiliates purchase verified corporate access from IABs and or have access to their own logs containing this information and use it to log directly into target networks which allows them to bypass perimeter defenses entirely. According to Verizon’s 2025 DBIR, 54% of ransomware victims had domain credentials in stealer logs before the attack. This makes it a lot less effort for ransomware groups to infiltrate organizations but can cause massive financial and reputational damage.
Account Takeover and Financial Fraud is another attack type which benefits from data included within stealer logs. Session cookies enable immediate account takeover without triggering MFA. Buyers can drain linked payment methods, redirect wire transfers, access cryptocurrency exchanges, and commit identity fraud without ever needing to use a credential or use sophisticated hacking techniques. This significantly lowers the barrier to entry for unsophisticated or “script kiddie” threat actors. Account takeover fraud totaled nearly $13 billion in 2023-2024.
The infostealer landscape shifted substantially in the second half of 2025 and into 2026, driven by a series of major law enforcement takedowns and the resulting scramble to fill vacated market share. But despite the takedowns, it has only grown with new stealer log families circulating all the time.
Following the disruption of LummaC2 in May 2025, established families moved quickly to absorb displaced activity. Rhadamanthys led through the summer until its own infrastructure was taken down by law enforcement in November 2025. By January 2026, Vidar 2.0 had emerged as the most widely used infostealer among threat actors, according to Flashpoint’s 2026 Global Threat Intelligence Report. As of early 2026, AhnLab ASEC’s February trend data identifies four families as dominating active distribution: LummaC2 (partially recovered), ACRStealer, StealC, and Vidar.
ACRStealer, also referred to as Acreed, is one of the most significant new entrants of 2025–2026, it rapidly ascended to become one of the top four most actively distributed infostealer families by early 2026
The macOS infostealer market has grown significantly from a niche concern into one of the fastest-expanding segments of the credential theft ecosystem. Atomic macOS Stealer (AMOS) dominated the macOS market through most of 2025, disappearing in October before returning in February 2026. MacSync (formerly Mac.C) emerged as the primary commodity macOS infostealer by year-end 2025. Poseidon and Odyssey are also active macOS-targeting families tracked in current reporting.
The table below highlights the most commonly observed stealer log families as of June 2026, including families that have rebranded or have been disrupted.

Products
Services
Use Cases