Stealer Logs: The Underground Commodity Powering Modern Cybercrime

July 23, 2026

A stealer log is not merely a log file. It is a structured, compressed archive of everything a piece of stealer malware has silently harvested from an infected device usually before the victim had any idea anything was wrong, if they ever did. Unlike ransomware, which announces itself with locked screens and ransom notes, infostealer malware operates without disrupting normal device function and therefore can be difficult to detect. The infected machine keeps running. The user keeps working. Meanwhile, the malware is methodically copying credentials from every browser, extracting active session cookies, reading cryptocurrency wallet files, and sometimes even photographing the desktop — then packaging everything into a neat archive and transmitting it to an attacker-controlled server.

Each log, in the language of underground markets, represents one “bot” — one compromised device, one victim’s complete digital footprint, ready for purchase and exploitation.

The value of a stealer log to a criminal depends heavily on what it contains. Logs with bank credentials, for instance, will be more valuable than other types of credentials. However, there are a lot of other data types withing a stealer log which can be very advantageous to criminals. Logs are typically organized by data type within the archive, making it simple for buyers to locate specific categories of value. The standard contents break down into six main categories:

  • Browser Credentials — Every saved username and password from any browser used on the infected machine such as Chrome, Edge, Firefox, Brave, and Opera, sorted by domain. One infection compromises dozens of accounts simultaneously.
  • Session Cookies & Auth Tokens — Active session tokens that bypass MFA entirely. An attacker importing a valid session cookie can access accounts without triggering any new authentication prompt.
  • Autofill & Payment Data — Names, addresses, phone numbers, dates of birth, and payment card details stored in browser autofill, enabling identity fraud beyond credential abuse. Think about this next time your browser asks you if you want to save your information for the future.
  • Cryptocurrency Wallets — Wallet files, browser extension data, seed phrases, and private keys for Bitcoin, Ethereum, and other cryptocurrencies. Funds can be drained within minutes of purchase.
  • System & Device Information — Hardware IDs, OS version, installed software, IP address, geolocation, and a desktop screenshot taken at infection time.
  • VPN, FTP & Application Tokens — Remote access credentials, FTP configs, and tokens for Slack, Discord, GitHub, and cloud services which can provide direct network footholds for corporate intrusions.

One particularly dangerous aspect of a stealer log infection is its attack on session persistence. When a user logs into a website and completes multi-factor authentication, the browser stores a session cookie confirming that the device has already authenticated. An attacker who imports that cookie can access the same account with no password required, and no MFA challenge triggered. Microsoft’s own documentation confirms that certain session cookies can persist until explicit logout or token expiration, potentially enabling weeks of undetected access with a single stolen log.

Sellers routinely re-package the same log multiple times — as a cheap raw dump, a premium corporate set, and a crypto-only slice — reselling the same victim data to multiple buyers. Underground market research suggests tens of billions of stolen cookies were circulating in 2025.

The infostealer malware ecosystem operates as a commercially organized, subscription-driven marketplace. Most major variants are sold as Malware-as-a-Service (MaaS), with developers offering monthly subscriptions, customer support forums, update bulletins, and affiliate programs. According to IBM X-Force’s 2025 threat intelligence report, the following families dominated dark web forum activity throughout 2024 and into 2025:

The broader pattern is consistent across every law enforcement disruption: when one major infostealer family is taken down, market share migrates to alternatives within days to weeks, or the malware is updated on new C2 servers run by other affiliates. This resilience stems from the structural nature of the ecosystem. Low development barriers, open-source code availability, and persistent criminal demand ensure that neutralizing any single actor creates an immediate commercial opportunity for others.

The underground market for stealer logs operates across several parallel channels, each serving different buyer profiles and transaction volumes. Understanding where logs are distributed is central to understanding how quickly stolen data can be weaponized after an infection.

Following the Genesis Market seizure in April 2023, SecureWorks documented a 670% increase in Russian Market activity as buyers and sellers migrated. This pattern has repeated across every major marketplace takedown: the criminal ecosystem absorbs the disruption rapidly, and within weeks, activity consolidates on surviving platforms or new entrants.

Stealer logs are usually the first step in an often more sophisticated attack. Information that can be found in logs is often used as part of other attacks, usually against organizations rather than against the individuals that were initially infected.

Initial Access Brokers (IABs) will sift through millions of logs, which they may control themselves or have purchased, looking specifically for corporate VPN credentials, SSO tokens, and domain admin access. Qualifying logs are re-packaged and sold on dark web forums for significantly higher prices.

Ransomware affiliates purchase verified corporate access from IABs and or have access to their own logs containing this information and use it to log directly into target networks which allows them to bypass perimeter defenses entirely. According to Verizon’s 2025 DBIR, 54% of ransomware victims had domain credentials in stealer logs before the attack. This makes it a lot less effort for ransomware groups to infiltrate organizations but can cause massive financial and reputational damage.

Account Takeover and Financial Fraud is another attack type which benefits from data included within stealer logs.  Session cookies enable immediate account takeover without triggering MFA. Buyers can drain linked payment methods, redirect wire transfers, access cryptocurrency exchanges, and commit identity fraud without ever needing to use a credential or use sophisticated hacking techniques. This significantly lowers the barrier to entry for unsophisticated or “script kiddie” threat actors.  Account takeover fraud totaled nearly $13 billion in 2023-2024.

The infostealer landscape shifted substantially in the second half of 2025 and into 2026, driven by a series of major law enforcement takedowns and the resulting scramble to fill vacated market share. But despite the takedowns, it has only grown with new stealer log families circulating all the time.

Following the disruption of LummaC2 in May 2025, established families moved quickly to absorb displaced activity. Rhadamanthys led through the summer until its own infrastructure was taken down by law enforcement in November 2025. By January 2026, Vidar 2.0 had emerged as the most widely used infostealer among threat actors, according to Flashpoint’s 2026 Global Threat Intelligence Report. As of early 2026, AhnLab ASEC’s February trend data identifies four families as dominating active distribution: LummaC2 (partially recovered), ACRStealer, StealC, and Vidar.

ACRStealer, also referred to as Acreed, is one of the most significant new entrants of 2025–2026, it rapidly ascended to become one of the top four most actively distributed infostealer families by early 2026

The macOS infostealer market has grown significantly from a niche concern into one of the fastest-expanding segments of the credential theft ecosystem. Atomic macOS Stealer (AMOS) dominated the macOS market through most of 2025, disappearing in October before returning in February 2026. MacSync (formerly Mac.C) emerged as the primary commodity macOS infostealer by year-end 2025. Poseidon and Odyssey are also active macOS-targeting families tracked in current reporting.

The table below highlights the most commonly observed stealer log families as of June 2026, including families that have rebranded or have been disrupted.

  • Infostealer malware stole 1.8 billion credentials in 2025, with IBM reporting an 84% year-over-year increase in phishing delivery of stealers.
  • Over half of ransomware victims in 2024-2025 had domain credentials in stealer logs prior to the attack, often with as little as a 48-hour window between log sale and intrusion.
  • Russian Market has emerged as the dominant venue for stealer log transactions, listing over 180,000 logs in H1 2025 and demonstrating consistent resilience to law enforcement pressure.
  • Session cookie theft renders MFA ineffective — 77% of logs on Russian Market contained SSO tokens in ReliaQuest’s analysis, making credential-only defenses insufficient.
  • Law enforcement operations against major infostealer families produce real but temporary disruption; the ecosystem reconstitutes rapidly due to low barriers to entry and consistent criminal demand.
  • Credential exposure from older logs carries persistent risk; stolen credentials remain valid and tradeable indefinitely unless explicitly revoked and rotated.

DarkOwl collects Stealer Log information from across the dark web and Telegram and makes this available through Vision so organizations can identify any credential exposure which may lead to further attacks. Contact us to learn more.

See why DarkOwl is the Leader in Darknet Data

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.