On this page

Inside the Infostealer Economy: How Stolen Credentials Become Corporate Access
12 min

Inside the Infostealer Economy: How Stolen Credentials Become Corporate Access

Cybercriminals no longer need to break through a company’s perimeter. They can buy the credentials, cookies and session tokens needed to log in as someone who already has access.

This is the business behind infostealers: malware designed to collect digital identity data from infected computers. The stolen information passes through an organized supply chain of malware developers, infection operators, data brokers, automated marketplaces and access sellers.

The malware itself is only the collection tool. The real product is access.

A single infected employee device can expose credentials for corporate email, cloud applications, customer platforms, internal tools and personal accounts. It may also reveal active browser sessions that allow an attacker to enter an account without repeating the normal password and multi-factor authentication process.

Understanding where this information is sold, who buys it and how its value is determined helps explain why infostealers have become one of the most direct paths into corporate environments.

Infostealers Have Become a Service Industry

Many infostealer developers operate through a malware-as-a-service model. Instead of using the malware themselves, they rent it to customers.

The developer maintains the code, adds features, works around security controls and provides a management panel where customers can create malware files and receive stolen data. Customers may also receive technical support, documentation and regular updates.

In the Raccoon Infostealer case, U.S. prosecutors said customers could rent access to the malware for approximately $200 per month, paid in cryptocurrency. This price covered the malware service. It did not include the value of any credentials later collected from infected computers.

Distribution can also be purchased separately. Operators use phishing messages, malicious advertisements, fake software, cracked applications, browser extensions and compromised websites to infect victims. Some pay specialized traffic providers or loader operators to deliver the malware for them.

This means a criminal can launch an infostealer campaign without developing malware, building delivery infrastructure or personally carrying out the eventual account takeover.

Each part of the attack can be outsourced.

What Infostealers Collect

The data taken from an infected device is commonly called an infostealer log.

A log may contain:

  • Saved usernames and passwords
  • Browser cookies
  • Active session tokens
  • Autofill information
  • Browsing history
  • Cryptocurrency wallet files
  • Email and messaging application data
  • Screenshots
  • IP addresses
  • Device identifiers
  • Operating-system and hardware details

This makes an infostealer infection different from a conventional third-party data breach.

A third-party breach usually exposes information stored by one company or online service. An infostealer collects information from the victim’s device across every service used through that device.

An employee may use the same browser to access corporate email, a customer relationship management platform, an identity provider, cloud infrastructure, social media accounts and personal services. The resulting log can connect all of those identities to one device and one individual.

For attackers, the context around the credentials is often as valuable as the password itself.

From an Infected Device to an Underground Market

Infostealer data usually passes through several hands before it is used in an attack.

The operator first receives the raw information through the malware’s control panel. Some operators search the logs themselves for valuable accounts. Others sell logs in bulk to aggregators, brokers or resellers.

These middlemen organize the data. They may identify credentials connected to banks, cryptocurrency platforms, government organizations or corporate domains. They may remove duplicates, categorize victims and check whether passwords or sessions still work.

The raw material is then divided into different products.

A seller might offer thousands of unprocessed logs as one package. Another might sell a single victim profile containing online banking credentials, email access and browser cookies. An access broker might take a working corporate VPN or cloud account and sell it privately to a ransomware group.

The closer a product is to confirmed, usable access, the more valuable it becomes.

Where Stolen Credentials Are Bought and Sold

The infostealer economy operates across forums, messaging platforms, automated shops and private networks. The phrase “dark web market” describes only part of it.

Cybercrime forums

Forums act as advertising, recruitment and reputation systems.

Infostealer developers announce new malware versions and subscription packages. Operators recruit affiliates and traffic providers. Sellers advertise stolen logs, and buyers request data connected to particular companies, industries or countries.

These forums may operate on Tor, on the open web or through a combination of both. Public posts often act as storefronts, while the actual negotiation moves to a private message or encrypted chat.

Trust is a constant problem. Vendors use reviews, transaction histories, escrow services and recommendations from established members to convince buyers that they will deliver the promised data.

RedLine and META Infostealer, for example, were advertised through criminal forums and Telegram before an international law-enforcement operation disrupted their infrastructure.

Telegram channels and groups

Telegram has become a major channel for advertising malware, publishing stolen data samples and selling logs.

Vendors create public channels to announce inventory and private groups for established customers. Automated bots can display available records, accept payments and deliver files. Direct messages are used to negotiate more valuable access.

Telegram is especially suited to infostealer data because the inventory loses value quickly. Sellers can publish newly collected logs and reach buyers immediately, without maintaining a complex marketplace.

The platform is also used by smaller vendors who lack the reputation or technical resources to operate a dedicated shop.

Automated log shops

Automated log shops organize stolen data like an online retail catalog.

Buyers may be able to filter victims by country, operating system, affected service, account type or corporate domain. Some platforms show which websites appear in the log and whether cookies or browser fingerprints are included.

Before it was seized in 2023, Genesis Market offered information taken from more than 1.5 million compromised computers and more than 80 million account credentials.

Genesis did not sell only usernames and passwords. Its products included browser cookies and device fingerprints that could help buyers imitate the victim’s normal digital environment.

That distinction matters. A login from an unfamiliar country and device may trigger a security challenge. A login accompanied by the victim’s cookies and browser characteristics may appear more legitimate.

General fraud marketplaces

Some marketplaces sell a broad range of criminal products, including credentials, malware, phishing tools, stolen identity documents, databases and hosting services.

These platforms connect infostealer sellers with buyers involved in account takeover, financial fraud, business email compromise and other crimes.

The inventory may include a mixture of fresh infostealer data, old breach records and repackaged credential lists. Buyers must judge whether the information is current, unique or even authentic.

Private access brokers

The most valuable corporate access is often sold privately.

A broker who finds working access to a company’s VPN, identity provider, cloud environment or remote administration system may approach selected buyers rather than advertise it openly.

Ransomware and extortion groups use initial-access brokers because purchasing access can be faster and less risky than carrying out the initial compromise themselves.

The infostealer operator generates the infection. The broker identifies a valuable corporate account. The final buyer uses it to enter the organization.

Credentials, Logs and Access Are Different Products

The underground market uses terms such as credentials, logs, bots and access, but these products carry very different levels of risk.

A credential list usually contains combinations of usernames and passwords. The data may originate from old breaches, password reuse, credential stuffing collections or infostealer logs. A large list can contain millions of records while offering very little usable access.

An infostealer log connects credentials to a specific infected device. It may include the infection date, device information, passwords, cookies and the services used by the victim.

A victim profile, sometimes called a bot, packages information from one computer into a product that a buyer can inspect and purchase.

Validated access means that a seller or broker has tested the account and confirmed that it still works.

This is why counting exposed passwords alone gives an incomplete picture. One fresh employee log with an active corporate session can create more immediate risk than millions of old consumer credentials.

Why Employee Infostealer Infections Carry Greater Risk

Credential exposure associated with customers and credential exposure associated with employees should not be treated equally.

A customer credential may create fraud, support costs and reputational risk. An employee credential may provide a route into the organization itself.

The risk increases when the exposure originated from an infostealer. The infection shows that data was taken directly from a device used by the employee. The attacker may have received passwords, sessions, device details and access to multiple corporate applications at the same time.

The employee’s position also matters. Credentials connected to administrators, finance teams, developers, executives and security staff may unlock sensitive systems or allow the attacker to impersonate a trusted person.

An employee may also have corporate credentials saved on a personal computer. This places the infection outside the company’s managed security environment while still exposing company access.

Traditional endpoint tools can only protect devices where they are installed. Exposure monitoring gives the organization visibility when its credentials appear in external breach and infostealer data, including incidents that originated from unmanaged devices.

Session Tokens Change the Meaning of Credential Theft

Multi-factor authentication provides strong protection against many password-based attacks. Infostealers have increased the importance of another target: authenticated sessions.

After a user successfully logs in, the service usually creates a session token or cookie. This tells the application that authentication has already occurred.

When an infostealer collects that session data, an attacker may be able to reuse it. The service may treat the attacker as the already authenticated victim, depending on the application’s security controls and the state of the session.

Changing the password may not immediately invalidate every active session. Removing the malware alone also does not revoke tokens that have already been stolen.

A complete response therefore requires more than a password reset. Security teams may need to revoke active sessions, rotate credentials, review authentication logs, remove unauthorized OAuth applications and investigate activity across every service accessed from the affected device.

Freshness Determines Value

Infostealer data is perishable.

Passwords change. Sessions expire. Accounts are suspended. Devices are cleaned. Security teams investigate suspicious activity. The value of a log usually begins to decline as soon as the data is stolen.

This makes speed central to the industry.

Operators want logs delivered immediately. Resellers want to process them before competitors. Buyers pay more for recent infections and active sessions. Some markets advertise records within hours of collection.

Fresh data also helps attackers act before a company knows that an infection occurred.

Historical breach data still matters, particularly for password reuse and credential-stuffing analysis. Its incremental value declines as passwords change and accounts disappear. Recent infostealer telemetry carries a different type of value: it can show that an active identity and device were compromised now.

Security teams need both historical context and fresh exposure data, but the response priority should reflect the difference.

What Makes a Log Valuable

There is no fixed price for an infostealer log. The value depends on what the buyer expects to gain from it.

Important factors include:

  • How recently the data was collected
  • Whether the password still works
  • Whether active cookies or session tokens are included
  • Whether the buyer can access the associated email account
  • The victim’s employer and role
  • The privileges attached to the account
  • Access to financial or cryptocurrency services
  • Whether device fingerprints are available
  • Whether the data has already been sold to other buyers
  • Whether the seller has validated the access

A raw consumer log may sell cheaply as part of a large collection. A verified administrator account for a valuable organization may be sold through a private negotiation.

Corporate access may also be exchanged for a percentage of the proceeds from a later ransomware or fraud operation.

The market prices outcomes, not records.

Why Takedowns Do Not Eliminate the Problem

International law-enforcement operations have disrupted major infostealer families and marketplaces, including Genesis Market, RedLine, META, Lumma, StealC and Amadey.

These actions can seize servers, expose operators and temporarily interrupt the flow of stolen data. They also force criminals to rebuild infrastructure and establish new reputations.

The wider market is difficult to eliminate because it is decentralized.

When one malware family disappears, operators move to another. When a forum closes, vendors migrate to Telegram or a replacement platform. When a public shop becomes risky, transactions move into invitation-only groups.

The industry does not depend on one developer, one market or one communication channel. It depends on continuing demand for working credentials and authenticated access.

As long as buyers are willing to pay for access, someone has an incentive to collect and sell it.

The Real Product Is a Stolen Digital Identity

An infostealer log is more than a password leak.

It can contain the different elements needed to impersonate a person online: credentials, email access, cookies, session tokens, browser information and device details.

Together, these elements form a stolen digital identity.

That identity can be used to take over accounts, bypass security checks, reset passwords, access company systems or establish a foothold for a larger attack.

Organizations therefore need to treat exposed employee credentials as an active security event. The response should account for how the data was stolen, how recently it appeared, which device was involved and which accounts or sessions may have been exposed.

Detecting Exposure Before It Becomes an Incident

Most companies cannot observe every device their employees use or every marketplace where credentials are traded.

They can monitor for evidence that their identities have already been exposed.

Lunar monitors infostealer logs and third-party breach data connected to an organization’s verified domains. It helps security teams identify affected accounts, understand whether an exposure came from an infostealer or a data breach and prioritize the events that create the greatest risk.

An employee exposure originating from an infostealer demands a different response from an old customer record found in a historical database leak. The source, freshness, employee relationship and available forensic context determine what the organization should do next.

The infostealer economy has made stolen access easy to package, sell and reuse. Companies need equivalent speed on the defensive side: visibility into exposed identities, enough context to understand the risk and a clear path from detection to action.

The attackers are already searching for working access.

Organizations should be able to see it first.

Ran Geva
Ran Geva rangeva
linkedin
Spread the news

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.