Introduction
Stealer logs represent the most dangerous commoditised threat to corporate security today. Unlike traditional data breaches that target specific organisations, infostealers cast a wide net across millions of users and machines, capturing everything from browser credentials to session tokens to cryptocurrency wallets in a single automated sweep.
So why are stealer logs such a critical concern right now? Because they are the common precursor to account takeover, ransomware deployment, and initial access brokerage. If your users’ credentials are in a stealer log marketplace, you do not have an identity problem; you have a breach waiting to happen.
This report examines what stealer logs are, how they are distributed and monetised, what data they contain, and how organisations can detect and defend against them. The scale is staggering: in the first half of 2025 alone, over 180,000 stealer logs were offered for sale on underground marketplaces. RedLine accounts for 44% of all logs collected. Vidar stole 65 million passwords in just six months.
If your domain appears in a stealer log, you are no longer operating under the assumption of credential compromise; you are operating under the certainty of it. The only question is whether the threat actor has already acted on that access.
How Infostealers Work
The Malware Itself
An infostealer is malware designed with a single purpose: to extract sensitive data from an infected machine and exfiltrate it to an attacker-controlled server. It runs silently, often with minimal resource consumption, which is why users and security teams can miss it for weeks or months.
So what data do they target? Browser autofill data, stored passwords, session cookies, saved payment card details, cryptocurrency wallet seed phrases and private keys, email account credentials, browser extensions, browsing history, installed software inventory, system information, and USB device history. The malware is indiscriminate; it grabs everything that might have value.
The sophistication varies. Basic infostealers are crude tools designed to grab whatever they can reach. Advanced infostealers include anti-analysis features, anti-virtualisation checks, geofencing to avoid high-risk jurisdictions, and code obfuscation to bypass signature-based detection.
Major Infostealer Families
RedLine is the dominant family by volume. First observed in 2020, RedLine has evolved into a modular stealer with customisable features, support for multiple languages and operating systems, and active development. It accounts for 44% of all stealer logs captured by intelligence vendors. RedLine spreads primarily through cracked software, malicious advertising networks, and watering hole attacks targeting development forums.
Raccoon was one of the earliest widespread infostealers and became infamous for its ease of use and low barrier to entry. Variant developers could build custom builds for under $100. Although law enforcement operations disrupted Raccoon’s primary infrastructure in 2023 (following the October 2022 arrest of developer Mark Sokolovsky), variants continue to circulate. Raccoon logs are heavily discounted on marketplaces because the payloads are dated and signatures are well-known.
Vidar is one of the most aggressive and feature-rich infostealers in circulation. It records keystrokes, captures screenshots, exfiltrates browser data, and includes anti-reverse-engineering protections. Vidar was responsible for stealing 65 million passwords in a documented six-month period from 2024 to 2025. It spreads through malvertising, cracked software, and compromised download mirrors.
Lumma emerged in 2022 and gained traction rapidly because of its effective distribution mechanism and low detection rates. Lumma’s primary distribution vector is Trojanised legitimate software (video converters, games, file managers) distributed through third-party sites. Lumma logs are actively traded on underground markets at premium prices because they tend to contain fresh, high-value data.

The Malware-as-a-Service Model
Most modern infostealers operate as a service, not a discrete product. Operators host the command and control infrastructure, provide a web panel for customers to manage infections and download logs, and take a percentage of the revenue when logs are resold.
The client (a threat actor, distributor, or criminal organisation) uses the service to build custom malware variants, deploy them through their chosen vectors, and collect the resulting logs. The service operator handles the backend; the client handles distribution and monetisation.
This model democratises malware development. You do not need to be a skilled reverse engineer or malware author; you just need access to a distribution channel and a payment method. Prices for malware-as-a-service access range from $40 per month for basic builds to $500 per month for fully customised, high-stealth variants with obfuscation and anti-analysis features.
The Stealer Log Supply Chain: From Infection to Marketplace
Step One: Distribution
The first stage of the supply chain is getting the malware onto the target machine. Distribution methods include cracked software (the single largest vector), malicious advertisements and browser redirects, compromised legitimate software mirrors, phishing emails with trojanised attachments, and watering hole attacks targeting developers and specific industries.
Cracked software remains the dominant distribution method because the economics are simple: users want free versions of expensive software, threat actors provide infected versions, and the malware runs with the privileges of the software installation. Commonly trojanised products include AutoCAD, Microsoft Office, Photoshop, Ableton Live, JetBrains IDEs, and antivirus software itself. Underground marketplaces such as zqi3evypxq7ok3gqnimwnlesf6v76ksrpgtgb6j7hh6ye752apzmceyd[.]onion advertise cracking tools and hacking guides alongside stealer logs.
Step Two: Execution and Exfiltration
Once executed, the infostealer begins its automated collection routine. It enumerates installed browsers, reads credential storage databases, decrypts stored passwords using the operating system’s credential storage APIs, extracts browser cookies (which often contain active session tokens for web services), and collects any data it has permissions to access.
So what happens to this data once collected? The malware packages it into an archive (typically JSON or CSV format), compresses it, and sends it back to the attacker’s command and control server. This happens in seconds to minutes, often without any user-visible activity. Encryption in transit is variable; some stealers use HTTPS, others use simple obfuscation.
Step Three: Log Curation and Testing
The logs arrive at the attacker’s server in raw form. Experienced threat actors filter and verify logs before offering them for sale. They test login credentials against target services to confirm validity, check whether emails are associated with high-value targets (executives, technical staff, security personnel), and flag logs that contain cryptocurrency wallet data or payment card information for premium pricing.
A high-quality stealer log contains verified working credentials, a mix of personal and corporate accounts, cryptocurrency wallet information, and identifiable metadata such as system username and company name extracted from the system registry. Low-quality logs are unverified, old (more than a week old), or contain duplicates.
Step Four: Marketplace and Distribution
Verified logs are uploaded to underground marketplaces. The three most significant distribution channels are the Russian Market (a Telegram-native marketplace with automated purchasing and delivery), Genesis Market (a long-standing marketplace specialising in session cookies and browser profile data, subject to FBI takedown in April 2023 as part of Operation Cookie Monster), and ad hoc Telegram channels run by individual threat actors or resellers.
Pricing follows a predictable pattern: individual consumer logs $1 to $5, logs containing cryptocurrency or payment card data $10 to $50, corporate or email logs $20 to $100, and bulk access to large log repositories $1,000 to $5,000, depending on scope and recency. Some marketplaces offer subscription models where buyers pay $200 to $500 per month for unlimited access to new logs.
Step Five: Exploitation
Once purchased, the logs are used for account takeover (directly accessing email, SaaS applications, or banking portals), credential stuffing attacks against non-customers, password spray attacks across corporate networks, identification of high-value targets for targeted phishing or social engineering, and sales to other threat actors, ransomware gangs, or initial access brokers.
The timeline from infection to exploitation can be remarkably short. Logs may be available for purchase within 24 to 72 hours of infection. Active threat actors monitor marketplaces continuously, purchasing logs for targets relevant to their operations immediately after they appear for sale.
What’s Inside a Stealer Log
A typical stealer log is a structured data archive containing the following categories of information.

Browser Credentials
Passwords are stored in Chrome, Firefox, Edge, Opera, and other Chromium-based browsers. These are extracted using the browser’s own decryption APIs and are usually in plaintext in the log. If your users are reusing passwords across multiple services (which most do), a single compromised password gives access to email, SaaS applications, banking portals, and corporate networks.
Session Cookies and Browser Data
Session cookies are particularly valuable because they often grant access to authenticated services without requiring the user to log in again. A stolen cookie for a user’s email account, for example, allows an attacker to reset the password for every service that user has signed up for. Logs also contain browser autofill data, saved addresses, phone numbers, and credit card information.
Cryptocurrency Wallet Data
If the infected machine has a cryptocurrency wallet installed (MetaMask, Trust Wallet, Ledger, Trezor drivers), the infostealer attempts to extract wallet seed phrases, private keys, and transaction history. A stolen seed phrase gives the attacker full control of any cryptocurrency stored in that wallet. Logs containing wallet data command a significant price premium, with cryptocurrency-focused marketplaces like tamazoncmlw2ohkbsmqxnotudejdd4befrasxuigzzjumqu3zba535yd[.]onion advertising cloned cards and financial fraud tools alongside wallet data.
System and User Information
The log includes the machine’s hostname, registered Windows username, installed software inventory, list of network interfaces and IP addresses, list of USB devices ever connected, system serial number, and BIOS information. This metadata helps threat actors profile the target (e.g. is this a developer machine, does it have security software installed) and tailor exploitation.
Email and Application Data
If Outlook, Thunderbird, or other email clients are installed, logs may contain saved email credentials and cached email headers. Application-specific data is also captured, including saved credentials in password managers (if they are not properly locked), FTP clients, SSH keys, browser extensions, and stored API credentials in development tools.
Indicator Format
Logs are typically structured as JSON or CSV files within a ZIP archive. A single log might be 5 to 200 megabytes, depending on the system’s history and installed software. Large batch log collections can reach gigabytes and are broken into smaller chunks for distribution.
Key Statistics: The Scale of the Threat
RedLine accounts for 44% of all stealer logs analysed by intelligence platforms. This concentration means that if you are looking for signs of compromise via stealer logs, you are primarily tracking RedLine activity. However, that also means a significant proportion of logs come from other families like Vidar, Lumma, and Raccoon variants.
Vidar stole 65 million unique passwords in a documented six-month period from October 2024 to March 2025. This single family, operating from a single set of infrastructure, compromised a staggering volume of user accounts across consumer and corporate domains.
Over 180,000 stealer logs were offered for sale on identified underground marketplaces in the first half of 2025. This is an average of 30,000 logs per month, or roughly 1,000 logs per day.
More than 50% of ransomware victims had their domains listed in stealer logs before the ransomware deployment. This indicates that initial compromise via stealer log access is a primary precursor to ransomware attacks. Threat actors purchase logs to establish initial access, conduct reconnaissance, and stage the ransomware payload.
Major Infostealer Families

Stealer Log Pricing by Type

Impact Statistics

The Marketplace Ecosystem
Russian Market (Telegram Native)
Russian Market operates exclusively within Telegram and is the largest active stealer log marketplace as of 2025. The platform uses automated bots that handle purchasing, payment, and log delivery. Buyers simply send a payment in cryptocurrency and receive a direct link to download the log within minutes.
Russian Market does not charge a commission on individual sales; revenue comes from premium marketplace memberships, advertising, and selective enforcement of seller verification. The platform lists 50,000 to 100,000 logs at any given time, with new inventory added continuously.
Genesis Market
Genesis Market is a longer-established marketplace that specialises in session cookies, browser profiles, and authenticated user sessions rather than raw passwords. It operates a traditional web interface (accessed via Tor) and enforces strict verification of sellers. Genesis Market was subject to a major FBI takedown operation in April 2023.
Genesis Market takes a 10 to 15% commission on each sale. Logs on Genesis command higher prices than equivalent logs on the Russian Market because the payload (authenticated sessions) is more directly useful for account takeover without password changes. The marketplace has hosted millions of stolen sessions.
Telegram Channels and Resellers
Smaller threat actors and resellers operate ad hoc Telegram channels, often promoting newly harvested logs from specific geographic regions or specific malware families. These channels operate with less formal infrastructure and offer discounts for bulk purchases. Forums like bfdxjkv5e2z3ilrifzbnvxxvhbzsj67akjpj3zc6smzr4vv6oz565gyd[.]onion host escrow services and enable peer-to-peer trading of stolen logs.
Prices on Telegram are often lower than those on centralised marketplaces because resellers are trying to move inventory quickly and avoid law enforcement attention. However, logs are also less verified and may contain duplicates or stale data.
Regional Variations
Pricing and availability vary significantly by geography. Logs from developed economies (USA, UK, Germany, Japan) command premium prices. Logs from developing economies are discounted. Logs are also segmented by corporate association; logs from email addresses on Fortune 500 domain whitelists are marked as such and priced accordingly.
Corporate Risk: How Stealer Logs Enable Attacks
Account Takeover
The most direct exploitation path is account takeover. An attacker purchases a log containing the email address and password of a corporate employee. They attempt to log into the employee’s email account. If multi-factor authentication is not enabled (and many users do not enable it outside of work contexts), login succeeds.
From the email, the attacker resets passwords for every service the employee has linked to that email account. This includes SaaS applications, cloud storage, password managers, and often the employee’s corporate VPN or SSO portal if they have reused the same password across services.
Initial Access Brokerage
Ransomware gangs and APT operators do not have time to run large-scale malware campaigns. Instead, they purchase access from initial access brokers. An initial access broker uses stealer logs to identify high-value targets (corporate email addresses, domain admin accounts, people working for specific industries), purchases logs for those individuals, and then sells the access to ransomware operators or nation states.
A single log containing credentials for a domain admin or security operations centre staff member can sell for $5,000 to $50,000 to a ransomware operator, because that access drastically shortcuts the reconnaissance and lateral movement phases of a ransomware campaign.
Reconnaissance and Lateral Movement
Even if the initial compromised account is a low-privilege user, logs contain system information, installed software, network configuration, and connected USB devices. This metadata gives threat actors a profile of the corporate environment before they even gain access. They know which security software is in use, which development frameworks are deployed, and which network devices are present.
Once inside, the attacker uses the compromised account to access email (containing sensitive business information, network topology diagrams, and access credentials in forwarded messages), network drives, and internal tools. This leads to lateral movement to higher-privileged accounts and eventually to domain admin compromise.
Credential Stuffing and Password Spray
An attacker with a database of 1,000 stolen passwords can conduct password spray attacks against your corporate email system or Active Directory, trying the same password across all known email addresses in your organisation. The attack succeeds if employees have reused credentials or used predictable variations.
This is a silent attack that happens outside of your firewall and VPN, so your network monitoring tools do not detect it. The first sign may be unexpected password reset emails or successful logins from impossible locations.
Supply Chain Compromise
If your organisation relies on third-party software vendors or contractors, and those vendors’ employees are in the stealer logs, an attacker can compromise the vendor and use their access to gain indirect access to your systems. This is a far easier attack vector than breaching you directly.
How SOS Intelligence Monitors Stealer Logs
Our breach alert system continuously monitors underground marketplaces, forums, Telegram channels, and data dump collections for stealer logs and other sources of compromised data. We extract indicators of compromise from each log and match them against your organisational domains.
So how does detection work? We parse log contents for email addresses, domain names, usernames, system names, and other identifying information. We match these against your organisation’s known domain list. When we find a hit, we generate an alert with details: which user was compromised, which malware family was responsible (if known), what data was exposed, when the log appeared for sale, and what price it commanded on the marketplace.
We also track trends. We monitor which malware families are producing the most volume, which geographic regions are being targeted, and which industries are disproportionately represented in current stealer logs. This gives you visibility into both specific risks to your organisation and the broader threat landscape.
Our enrichment process adds context. We cross-reference the compromised email addresses with LinkedIn, WHOIS records, and internal threat intelligence to identify whether the compromised user holds a sensitive position (executive, developer, security staff). We flag logs that contain multiple compromised employees from the same organisation as indicators of targeted activity rather than random harvesting.
Defensive Recommendations

Detection and Monitoring
First: subscribe to breach alert services that monitor stealer log marketplaces and dark web collections. The earlier you know that your users are in stealer logs, the faster you can reset compromised credentials and audit for account access.
Second: implement continuous exposure monitoring. Track your organisational domains on dark web forums, marketplaces, pastebins, and leaked database collections. Many of these sources post publicly (just on obscure infrastructure); you do not need access to Telegram to find them.
Incident Response
If you discover that your domain is present in a stealer log, treat it as a credential compromise incident. Reset the password for the compromised user immediately. Force re-authentication on all active sessions (log them out everywhere). Enable multi-factor authentication if not already in use. Audit email forwarding rules, application integrations, and connected devices for signs of access.
Check whether the compromised user holds a sensitive role. If they do, expand your investigation: query your identity provider and email system for impossible logins, password changes, or unusual activity; check cloud storage for data exfiltration; and interview the user about recent phishing attempts or unusual system behaviour.
Credential Hygiene
Enforce strong, unique passwords for all systems, especially email and identity providers. Implement passwordless authentication where possible (FIDO2 hardware keys, Windows Hello). Where passwords are necessary, use a password manager with strong master passwords.
Multi-factor authentication is not optional; it is mandatory. If an attacker has your password (because it is in a stealer log), multi-factor authentication is the only thing that stops account takeover. Prioritise MFA for email and administrative accounts. Do not rely on SMS; use TOTP or hardware keys.
Threat Actor Knowledge
Understand which threat actors are currently targeting your industry. If you operate in critical infrastructure or financial services, you are targeted by state-sponsored actors and organised crime groups, not opportunistic cybercriminals. If you operate in technology or biotech, intellectual property theft is a primary motivation.
Review the malware families affecting your sector. If your users are appearing in Vidar or Lumma logs more frequently than average, your distribution channels may be compromised. If you see your domain in logs associated with a specific ransomware gang, you have a higher probability of imminent encryption activity.
Third-Party Risk
Audit your third-party vendors and contractors for Stealer log exposure. If a critical vendor has employees in breach, consider the implications for your access. Do they reuse passwords, or are their systems segmented? Do they have elevated privileges in your environment?
Implement zero-trust principles for vendor access. Do not assume that a contractor’s machine is clean; segment their access, require multi-factor authentication, and monitor their activity as you would a hostile external party.
Appendix: DARKSEARCH Observed Indicators
The following table documents confirmed indicators from dark web marketplaces and forums monitored via SOS Intelligence’s DARKSEARCH API. All onion addresses are defanged for security and compliance purposes. These indicators are provided for threat intelligence and detection purposes only.

External References
The analysis in this report draws on publicly available threat intelligence, academic research, and law enforcement activity reports. Key sources include:

Conclusion
Stealer logs are not a future threat; they are a present reality. The scale of harvesting, the sophistication of the malware, and the availability of stolen data on open marketplaces mean that credential compromise is no longer exceptional. It is expected.
Your organisation’s security posture must start with the assumption that your users’ credentials are compromised. That means: strong, unique passwords, multi-factor authentication, continuous monitoring of dark web sources, rapid response to breach alerts, and zero-trust policies for sensitive access.
The defenders who will prevail are those who detect compromise early and respond immediately. Every hour between when a stealer log appears on a marketplace and when you reset the compromised credentials is an hour the attacker can exploit that access.
If you do not have visibility into dark web stealer log marketplaces today, you do not have a complete picture of your organisation’s actual risk. Close that gap now.
Danger photo by Edwin Hooper on Unsplash
Malware photo by Ed Hardie on Unsplash
Browser photo by BoliviaInteligente on Unsplash
No trespassing photo by Joseph Corl on Unsplash



































Recent Comments