Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical RCE in TP-Link Omada ER605 VPN Routers Exposes Hotel Guests
July 24, 2026
InfoStealer Logs Fuel Massive Cloud Data Breaches
July 24, 2026
Lampion RAT Malware Hidden in Fake Payment Receipt Emails
July 24, 2026
Home/CyberSecurity News/InfoStealer Logs Fuel Massive Cloud Data Breaches
CyberSecurity News

InfoStealer Logs Fuel Massive Cloud Data Breaches

Key Takeaways Infostealer malware has become the primary initial access vector for enterprise breaches, surpassing traditional phishing and exploits. Threat actors leverage stolen credentials and...

Emy Elsamnoudy
Emy Elsamnoudy
July 24, 2026 10 Min Read
2 0

Key Takeaways

  • Infostealer malware has become the primary initial access vector for enterprise breaches, surpassing traditional phishing and exploits.
  • Threat actors leverage stolen credentials and session cookies, often purchased from underground markets, to directly access cloud services and SaaS platforms.
  • The absence of multi-factor authentication (MFA) and poor credential hygiene are critical enablers for these attacks, as exemplified by the 2024 Snowflake breach.
  • Organizations must prioritize identity resilience, including strong MFA, continuous access evaluation, and proactive monitoring for leaked credentials, to defend against this pervasive threat.

Infostealer Logs Fuel Massive Cloud Data Breaches

Infostealer malware has emerged as the dominant initial access commodity within the cybercrime ecosystem, effectively displacing traditional phishing campaigns and exploit-driven intrusions as the primary precursor to enterprise breaches and ransomware attacks. Instead of actively breaking into networks, modern threat actors now frequently purchase “stealer logs” containing valid usernames, passwords, session cookies, and single sign-on (SSO) tokens harvested from compromised endpoints. These logs enable direct access to cloud consoles, SaaS platforms, and VPN gateways by replaying stolen sessions.

Table Of Content

  • Key Takeaways
  • Infostealer Logs Fuel Massive Cloud Data Breaches
  • From a Single Compromised Laptop to a Billion-Record Breach
  • The Infostealer-to-Breach Kill Chain
  • Known Infection Vectors
  • Known Tools and Malware Families Used
  • Targeted Industries
  • Common Vulnerabilities and Weaknesses Exploited
  • Detection Behaviors for Defenders
  • Indicators of Compromise (IOCs)
  • What You Should Do

Data from Cisco Talos’ Q1 2026 incident-response reports confirms a significant shift, with phishing and credential-based access now leading as the top initial-access vectors. The vast majority of these credentials are derived from infostealer logs, underscoring the malware’s pivotal role in the current threat landscape. This report delves into the complete kill chain, from initial infection to full cloud compromise, offering a comprehensive reference for defenders on known infection vectors, malware families, targeted sectors, exploited weaknesses, and indicators of compromise (IOCs).

From a Single Compromised Laptop to a Billion-Record Breach

The 2024 Snowflake breach serves as a stark illustration of this attack methodology. Threat actor UNC5537, also known as Scattered Spider or ShinyHunters, did not exploit a vulnerability within Snowflake’s platform. Instead, they utilized credentials obtained through infostealer malware from Snowflake customer employees. Some of these infections dated back to 2023, with passwords often found stored insecurely in spreadsheets and password managers. Crucially, none of the compromised accounts had multi-factor authentication (MFA) enabled, allowing attackers to log in using only a stolen username and password.

This campaign ultimately impacted at least 165 organizations, including major entities like AT&T, Ticketmaster, Santander Bank, Neiman Marcus, and Advance Auto Parts. The fallout included the exposure of over 50 billion AT&T call records and extortion demands exceeding $2 million. UNC5537 deployed a specialized exfiltration toolkit named FROSTBITE to automate large-scale data scraping once inside the Snowflake instances.

A more recent incident, the Zestix/Sentap campaign identified in January 2026, employed credentials harvested by RedLine, Lumma, and Vidar infostealers. This enabled breaches of corporate accounts on cloud file-sharing platforms such as ShareFile, Nextcloud, and OwnCloud. Attackers successfully exfiltrated sensitive defense engineering blueprints, healthcare records, and legal and financial archives. Again, no exploits were involved; access was gained solely through stolen credentials and the absence of MFA.

The sheer scale of this threat is quantified by Flare’s 2026 State of Enterprise Infostealer Exposure report, which revealed 2.05 million infostealer logs exposed enterprise identity credentials in 2025 alone. Enterprise identity exposure in infected logs surged from approximately 6% in early 2024 to nearly 16% by 2026, with a staggering 79% of these enterprise logs containing Microsoft-linked SSO credentials. Furthermore, roughly 1.17 million logs contained both credentials and live session cookies, providing immediate access that completely bypasses MFA through session replay.

The Infostealer-to-Breach Kill Chain

This sophisticated attack pipeline unfolds across five distinct stages, each often managed by different specialized actors within the cybercrime supply chain:

  1. Infection: A user, typically operating on a personal or unmanaged device, executes the stealer payload. This usually occurs via a low-effort but high-volume social engineering lure.
  2. Collection: The malware systematically harvests browser-stored passwords, session cookies, autofill data, cryptocurrency wallets, and system fingerprints. These are then packaged into a ZIP archive, known as a “log,” for each victim device.
  3. Exfiltration: The collected log is transmitted to the operator. The Telegram Bot API has become the prevalent command-and-control (C2) channel due to its cost-effectiveness, resilience to takedowns, and ability to blend with normal network traffic.
  4. Bulk Sale: Logs are then dumped in high volumes onto automated underground marketplaces such as Russian Market, 2easy, STYX, and DarkForums. Prices can be as low as $1–$50 per log.
  5. Filtering and Brokerage: Initial Access Brokers (IABs) purchase these logs in bulk, filtering for those containing valuable enterprise VPN, SSO, or cloud-admin credentials. They verify the access still functions and then resell it privately to ransomware affiliates for $500–$5,000, depending on the level of privilege and the targeted sector.

Credentials typically move from the point of theft to an underground listing within 48 hours. Ransomware affiliates have been observed weaponizing purchased access within 48 hours of an IAB listing going live. This rapid timeline necessitates continuous credential-leak monitoring, rather than merely periodic password rotation, as a fundamental defensive requirement for organizations.

Log Breach Lifecycle
Log Breach Lifecycle (Image Source: Cybersecuritynews.com)

Known Infection Vectors

Most Active Infostealer Families Fueling Cloud Breaches
Most Active Infostealer Families Fueling Cloud Breaches (Image Source: Cybersecuritynews.com)

By 2026, infostealer operators have largely abandoned exploit-based delivery in favor of social-engineering lures optimized for high volume rather than persistence:

  • ClickFix / Fake CAPTCHA Pages: Victims are instructed to “verify you’re human” by pressing Win+R and pasting a clipboard string. This string is actually a PowerShell command that silently downloads the malicious loader. This technique now drives the CastleLoader-to-Lumma infection chain.
  • Trojanized Cracked/Pirated Software: SEO-poisoned search results for terms like “[software] crack” or “[game] cheat” lead users to installers embedded with malware. This remains a highly effective, long-running vector for Lumma, RedLine, and StealC.
  • Fake Browser or Codec Updates: Spurious “Chrome is out of date” prompts deliver signed or short-lived-certificate installers containing the infostealer.
  • Malvertising and YouTube Tutorial Links: “How to get free [software]” videos on YouTube often link to password-protected archives in their descriptions, a method used to evade antivirus scanning.
  • Phishing Emails with Malicious Attachments: This remains a top-tier vector, particularly for targeted enterprise delivery.
  • Malicious npm/Open-Source Packages: A growing trend involves supply-chain-style delivery to plant stealers on developer machines.

Known Tools and Malware Families Used

A limited number of Malware-as-a-Service (MaaS) families are responsible for the overwhelming majority of stealer-log volume traded in 2026:

Family Role/Notes Status in 2026
Lumma Stealer Market leader; evades detection, targets passwords, cookies, crypto wallets; now paired with CastleLoader Resurgent after 2025 law-enforcement disruption
Vidar Durable, long-running MaaS family, related lineage to StealC Stubbornly persistent
StealC MaaS, believed linked to Vidar developers; harvests broad credential set Actively disrupted by Microsoft DCU in June 2026
RedLine Pioneer of the MaaS stealer model; legacy footprint still surfaces in old logs Crippled by Operation Magnus, late 2024
Amadey Loader used to stage follow-on stealers Taken down alongside StealC by Microsoft, June 2026
Raccoon Broad credential/cookie harvester, active in bulk log markets Ongoing
CastleLoader Loader delivering Lumma via ClickFix chains Surging since late 2025
Atomic Stealer (AMOS) macOS-focused; distributed via pirated Mac apps Growing on macOS

CastleLoader-delivered LummaStealer campaigns have impacted over 100,000 potential victims, with hundreds of associated malicious domains and IP addresses observed through DNS telemetry. Microsoft’s Digital Crimes Unit (DCU) takedown of StealC and Amadey infrastructure in June 2026 highlights a common outcome: such disruption operations tend to shift market share to remaining families rather than eliminating the entire ecosystem.

Infection Vectors And Tooling
Infection Vectors And Tooling (Image Source: Cybersecuritynews.com)

Targeted Industries

Industries most Targeted via Stolen-Credential Attacks
Industries most Targeted via Stolen-Credential Attacks (Image Source: Cybersecuritynews.com)

Access gained through infostealers is priced and prioritized based on the target industry, with higher premiums for sectors holding valuable data or significant operational leverage. Cyfirma’s June 2026 ransomware tracking indicates that Professional Goods & Services was the most targeted sector (45 incidents), followed by Manufacturing (35), Healthcare (25), Real Estate & Construction (19), Consumer Goods & Services (18), Finance (16), and Government & Civic (14).

Analysis of underground marketplace pricing consistently shows that access linked to healthcare, manufacturing, and financial services commands the highest prices. This reflects both the sensitivity of data in these sectors and the higher likelihood of ransom payments. IBM X-Force data reveals Manufacturing has held the top spot as the most targeted industry for four consecutive years, while healthcare bears the highest average breach cost at $7.42 million.

Attackers increasingly favor industries characterized by complex, extensive digital infrastructure and numerous third-party dependencies. This includes software development environments, cloud platforms, hosting infrastructure, and shared-service ecosystems, where a single compromised credential can cascade and affect multiple downstream customers.

Targeted Sectors And Assets
Targeted Sectors And Assets (Image Source: Cybersecuritynews.com)

Common Vulnerabilities and Weaknesses Exploited

Crucially, most cloud breaches fueled by infostealers do not involve software vulnerabilities or zero-day exploits. Instead, the “exploit” is organizational rather than technical:

  • Absent or Non-Enforced MFA: This is the single most significant enabling factor. The Snowflake breach, for example, succeeded entirely because no compromised account had MFA enabled.
  • Session Cookie / Token Replay: Stolen SSO and browser session cookies allow attackers to completely bypass authentication, as the session was already authenticated prior to theft. In 2025, 1.17 million logs contained live session cookies alongside credentials.
  • BYOD and Unmanaged Personal Devices: Infections frequently occur on personal machines used for corporate SaaS or email access, often operating outside the visibility of Endpoint Detection and Response (EDR) and conditional access policies.
  • Credential Reuse and Plaintext Storage: Credentials stored in spreadsheets, password managers, or reused across personal and corporate accounts, as documented in the Snowflake case, are prime targets.
  • Lack of Device-Posture-Based Conditional Access: Sessions from unmanaged or non-compliant devices are accepted for sensitive cloud applications when device-trust policies are not properly enforced.
  • Excessive OAuth/SSO App Grants: Unreviewed delegated permissions on SaaS integrations create lateral pivot paths once an identity is compromised.
  • Weak or Absent Continuous Access Evaluation (CAE): Sessions are not automatically revoked upon changes in IP address or risk signals, allowing replayed cookies to remain valid.

MITRE ATT&CK maps this behavior primarily to Credential Access (TA0006), specifically T1555 – Credentials from Password Stores and its sub-technique T1555.003 – Credentials from Web Browsers, which covers the theft of saved browser passwords, cookies, and autofill data. Related techniques include T1056 (Input Capture/keylogging) and T1557 (session/token interception), both commonly observed across current infostealer families.

Identity Weaknesses And Controls
Identity Weaknesses And Controls (Image Source: Cybersecuritynews.com)

Detection Behaviors for Defenders

Given that MaaS operators frequently rebuild binaries and issue customer-specific variants, signature-based detection is often unreliable. Behavioral detection is therefore essential. Recommended detection priorities include:

  • Outbound POST traffic to api.telegram.org (particularly /bot<TOKEN>/sendDocument) from any process other than the legitimate Telegram client. This is the highest-signal indicator across nearly all current stealer families.
  • Non-browser processes accessing Chrome/Edge/Firefox profile directories, especially Login Data, Cookies, Web Data, and Local State files (MITRE T1555.003).
  • Non-Telegram processes accessing the Telegram Desktop tdata folder, which can grant full account takeover without a password or 2FA.
  • Unexpected execution of mshta.exe, powershell.exe, or wscript.exe shortly after a user-initiated download, which is a classic signature of ClickFix/CastleLoader campaigns.
  • High-frequency GetAsyncKeyState API polling from processes not related to input, indicating the presence of keylogger modules.
  • Sudden “new sign-in from unfamiliar location” alerts, unexpected password-reset emails, or the appearance of unfamiliar browser extensions post-infection.

Indicators of Compromise (IOCs)

The following IOC categories are derived from active threat intelligence tracking of the CastleLoader/Lumma and related 2025–2026 stealer campaigns. Due to the rapid infrastructure rotation by MaaS operators and the use of per-customer builds, defenders should consider static IOCs as short-lived. Prioritize the behavioral detections mentioned above alongside continuous threat intelligence feed subscriptions.

Network infrastructure indicators:

  • C2 exfiltration channel: Outbound connections to api.telegram.org from non-Telegram processes should be treated as critical alerts. Associated infrastructure ranges include 149.154.167.0/24 and 91.108.4.0/22.
  • CastleLoader/LummaStealer campaigns are linked to hundreds of malicious domains and IP addresses observed via DNS telemetry, generated through fast DNS rotation. Organizations should acquire current indicator feeds from ThreatFox’s CastleLoader family page (28 tracked IOCs as of January 2026) and Palo Alto Unit 42’s published Lumma/ClickFix IOC bulletins, rather than relying on static lists, given the rapid infrastructure churn.

File-system / host indicators:

  • Non-Telegram process access to Telegram Desktoptdata.
  • Common staging paths observed across current stealer families: %TEMP%keys.log, %TEMP%screen.jpg (Fox Stealer); Chrome_Passwords.db / Edge_Passwords.db written to temporary directories (Joker SHELL); and the Blank-[username].rar archive naming convention (Blank Grabber).
  • Unexpected creation of ZIP/RAR archives immediately following browser-data access, consistent with log packaging prior to exfiltration.

Marketplace/exposure indicators:

  • Organizational email domains or corporate SaaS/VPN URLs appearing in stealer-log listings on Russian Market, 2easy, STYX, or DarkForums. This should be monitored via continuous domain-watch services such as Flare, Hudson Rock, SpyCloud, Constella, or IntelX.
  • Telegram channels advertising “LOGS” bundled with sector-specific keywords (finance, healthcare, government) targeting a victim organization’s industry.
  • Free lookup resources for individual exposure checks: Have I Been Pwned (which indexes stealer-log corpora) and domain-level services such as Stealercheck.

Behavioral / process indicators:

  • MITRE ATT&CK T1555.003 (Credentials from Web Browsers) triggering on browser credential-store file access by non-browser binaries.
  • Anomalous SSO/cloud-console logins immediately following a known device infection event, especially from IP geolocations inconsistent with the employee’s normal pattern.
Host And Browser Artifacts
Host And Browser Artifacts (Image Source: Cybersecuritynews.com)

What You Should Do

Since the primary enabler for these attacks is almost always identity and access management vulnerabilities rather than patchable software flaws, mitigation strategies must focus on identity resilience over traditional perimeter defenses:

  • Enforce Phishing-Resistant MFA: Implement FIDO2/WebAuthn hardware keys for all cloud consoles, VPNs, and SSO providers. Session replay cannot defeat a physical key bound to the domain.
  • Enable Continuous Access Evaluation (CAE): Utilize solutions like Microsoft Entra ID CAE to force re-authentication upon changes in IP address or risk signals, thereby invalidating replayed cookies.
  • Require Managed Device Status: Mandate compliant or managed device status for access to sensitive SaaS applications such as Exchange, SharePoint, and Azure portal, blocking sessions from unmanaged BYOD devices.
  • Subscribe to Continuous Infostealer Exposure Monitoring: Use services from providers like Flare, Hudson Rock, SpyCloud, or Constella to proactively query organizational domains against leaked-log corpora.
  • Audit and Revoke Excessive OAuth/SSO App Grants: Regularly review and revoke unnecessary delegated application permissions across your Microsoft 365 or Okta tenant.
  • Vault and Rotate Service Account Secrets: Quarterly rotate and securely vault service account secrets using solutions such as HashiCorp Vault or Azure Key Vault.
  • Treat Confirmed Infections as High-Severity Incidents: Any confirmed infostealer infection must be treated as a critical precursor event, necessitating immediate credential rotation and full session revocation across every account accessed from the compromised device, not merely as a malware cleanup task.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCybersecurityExploitMalwarePatchphishingransomwareSecurityVulnerabilityzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Lampion RAT Malware Hidden in Fake Payment Receipt Emails

Next Post

Critical RCE in TP-Link Omada ER605 VPN Routers Exposes Hotel Guests

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft detects 7.6B email phishing threats, Teams vishing up 10x
July 24, 2026
Russian Hackers Exploit Critical Zimbra Zero-Day to Steal Emails
July 24, 2026
Decathlon Investigates Alleged Breach of 160 Million Customer Records
July 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us