On this page

Windows Commodity Infostealers: The Malware Behind the Modern Credential Theft Economy
19 min

Windows Commodity Infostealers: The Malware Behind the Modern Credential Theft Economy

Infostealers have become one of the most important malware categories in cybercrime. Their role is simple and powerful: infect a device, collect valuable identity and account data, package it into a “log,” and send it to the attacker. A single infection can expose browser passwords, session cookies, autofill data, crypto wallets, screenshots, desktop files, VPN credentials, messaging tokens, email accounts, FTP clients, and other application secrets. Once stolen, this data can be used directly for fraud or sold to other criminals who specialize in account takeover, business email compromise, ransomware access, identity theft, or crypto theft.

Windows remains the largest operating environment for commodity infostealers. The reason is practical. Windows dominates corporate endpoints, gaming PCs, personal laptops, contractor devices, and developer workstations. Many of these machines hold the exact data criminals want: saved browser sessions, SaaS access, cloud console cookies, VPN profiles, password manager artifacts, crypto wallets, and messaging accounts. Red Canary describes stealers as malware designed to collect data from victim systems and highlights that stealer activity surged in 2025, driven in part by malware-as-a-service families such as LummaC2 and Rhadamanthys.

Windows commodity stealers sit at the center of a larger underground economy. Operators distribute malware through fake installers, cracked software, malicious ads, phishing, fake CAPTCHA pages, “paste-and-run” social engineering, Telegram channels, file-sharing sites, SEO poisoning, and loader malware. The stealer runs, collects data quickly, exfiltrates it, and produces a structured package that can be resold. The buyer of that package may have no involvement in the original infection. This separation of roles makes the infostealer ecosystem scalable: one group builds the malware, another distributes it, another sells logs, and another monetizes access.

Kaspersky’s 2025 Digital Footprint Intelligence reporting describes infostealers as malware that extracts credentials, cookies, financial details, and other valuable information into log files. Its 2020-2024 analysis found that RedLine caused the most infections in 2024, followed by RisePro and Lumma, while its public summary states that RisePro and StealC were among the fastest-growing infostealers.

What makes Windows commodity stealers different

Windows commodity stealers are built for scale. They are usually sold or rented as malware-as-a-service, complete with web panels, documentation, updates, support channels, and configuration options. Their success depends on reach, reliability, ease of deployment, and the quality of the logs they produce. The most successful families behave less like one-off malware projects and more like criminal software products.

This product mindset matters. A stealer that extracts more browsers, supports more wallets, bypasses more security controls, and produces cleaner logs becomes more valuable to affiliates. A family that adds frequent updates can survive browser changes, endpoint detections, and law-enforcement disruptions. CSO Online reported that popular stealers such as Vidar, Lumma, and Meduza have pushed consistent releases and updates, adapting to browser security changes in a way that resembles normal software development teams.

Windows commodity stealers also have a direct relationship with identity-based attacks. Password theft is only part of the story. Session cookies and browser profiles are often more valuable because they can give attackers access to already-authenticated accounts. A stolen session can help bypass multi-factor authentication, especially when the account session remains active. This makes stealer logs useful for cloud account takeover, SaaS intrusion, advertising fraud, social media hijacking, and ransomware initial access.

How a typical Windows stealer infection works

A typical Windows infostealer campaign starts with a lure. The victim may search for a cracked application, download a fake browser update, open a malicious attachment, follow a sponsored search result, solve a fake CAPTCHA, or run a command copied from a web page. In many recent campaigns, the attacker’s goal is to make the victim execute code willingly while believing they are installing software, fixing a browser issue, or proving they are human.

Once executed, the stealer usually profiles the system and searches for valuable local data. It may read browser databases, decrypt stored credentials where possible, collect cookies, enumerate browser extensions, search for wallet files, capture autofill data, scrape desktop and document folders, collect system metadata, and take screenshots. Some families also collect Telegram, Discord, Steam, FileZilla, WinSCP, VPN, email client, and password manager artifacts. Red Canary notes that modern stealers commonly target browser credentials, FileZilla, WinSCP, Telegram, Steam, crypto wallets, VPN profiles, cloud CLI configurations, and sensitive files from common user folders.

After collection, the malware compresses the stolen data and sends it to the attacker. Exfiltration may happen through HTTP requests to command-and-control infrastructure, Telegram bots, Discord webhooks, FTP, SMTP, or dedicated stealer panels. The attacker receives a log that contains credentials, cookies, device details, IP information, installed software, and sometimes screenshots or files. These logs then move through underground marketplaces, private Telegram channels, access broker networks, and fraud communities.

The leading Windows commodity stealer families

The Windows stealer ecosystem changes constantly, but several families define the current and recent landscape. Lumma, RedLine, Raccoon, Vidar, StealC, RisePro, Rhadamanthys, FormBook/XLoader, Agent Tesla, Snake Keylogger, AZORult, Pony, LokiBot, Mars Stealer, Aurora, Mystic, Meduza, BlackGuard, DarkCloud, StrelaStealer, Ducktail, NodeStealer, and FickerStealer are among the families security teams regularly encounter or track.

Lumma, also called LummaC2, became one of the most prominent modern Windows stealers. Microsoft led a global disruption action against Lumma in May 2025 and said it identified more than 394,000 Windows computers infected between March 16 and May 16, 2025. Microsoft also stated that it severed communications between the tool and victims as part of the action. This scale shows why Lumma became a reference point for modern stealer operations. It combined broad credential theft, criminal usability, affiliate adoption, and a mature service model.

RedLine was one of the most dominant stealers of the early 2020s. It became widely used because it was accessible, reliable, and effective against common browser and application data. It was distributed through cracked software, phishing, fake installers, and other commodity channels. In October 2024, Operation Magnus disrupted the RedLine and META infostealer operations, with participation from the Dutch National Police, the FBI, and other international partners. RedLine’s long run made it one of the clearest examples of how malware-as-a-service can industrialize credential theft.

Raccoon Stealer, also known in some phases as RecordBreaker, followed a similar commodity model. It targeted browser data, credentials, cookies, crypto wallets, and application data, and it became a common name in stealer-log markets. Raccoon’s history also illustrates how a brand can fade, return, change infrastructure, or resurface under related naming as law enforcement pressure, competition, and operator disruption reshape the market.

Vidar is another long-running Windows stealer with strong historical relevance. It has often been discussed in relation to the older Arkei lineage and is known for broad collection of browser credentials, cookies, crypto wallet data, application credentials, screenshots, and system information. Vidar has remained relevant because it fits well into common distribution ecosystems and has continued to appear in campaigns even as newer families gained attention.

StealC is a newer family that gained momentum as criminals looked for updated alternatives to older stealers. Kaspersky’s public 2025 summary identifies StealC as one of the fastest-growing infostealers, and its broader analysis places it among the families shaping recent infection patterns. StealC is important because it reflects the market’s constant renewal cycle. When one stealer declines, gets disrupted, or becomes heavily detected, another product can absorb demand.

RisePro also grew quickly and became a major 2024 presence. Kaspersky’s 2020-2024 analysis found that RedLine caused the most infections in 2024, followed by RisePro and Lumma. RisePro’s rise shows how fast a family can become relevant when it combines working collection features, effective distribution, and underground adoption.

Rhadamanthys represents the more sophisticated end of the Windows stealer market. It has been described as modular and capable, with broad data theft functionality. In November 2025, Europol announced that Operation Endgame targeted Rhadamanthys, VenomRAT, and the Elysium botnet, calling Rhadamanthys one of the biggest infostealers and stating that the targeted infrastructure played a key role in international cybercrime. Rhadamanthys shows that infostealers are no longer only low-sophistication malware. Some families now operate with mature infrastructure, modular design, and broad downstream criminal use.

FormBook and XLoader occupy a different but equally important place in the ecosystem. FormBook is a long-running credential stealer and form grabber, while XLoader is widely treated as its successor or closely related follow-on in many security reports. These families have been used in phishing-heavy campaigns and remain relevant because they combine credential theft, form grabbing, keylogging, screenshots, and broad exfiltration options.

Agent Tesla is a .NET keylogger and infostealer that has remained active for years. Malpedia describes Agent Tesla as malware that can steal keystrokes, clipboard data, credentials, and other information, and can exfiltrate data through HTTP(S), SMTP, FTP, and Telegram. Agent Tesla remains important because it is widely used in email-based campaigns, especially against businesses that still face a steady stream of malicious attachments and invoice-themed lures.

Snake Keylogger, also known as SnakeStealer or 404 Keylogger in some reporting, is another common Windows credential stealer and keylogger. It is often delivered through phishing attachments and targets saved credentials, keystrokes, screenshots, clipboard data, and browser information. It represents the large group of stealers that may receive less attention than Lumma or RedLine but still create a serious operational burden for security teams.

AZORult, Pony, and LokiBot are older families that shaped the commodity stealer model. Pony, also known as Fareit, became one of the classic credential theft tools. AZORult became known for browser and wallet theft. LokiBot gained wide adoption through phishing and commodity malware distribution. These families matter for historical context because many newer stealers reused the same basic value proposition: steal credentials from many machines, package them efficiently, and sell the results.

Comparison table: major Windows commodity stealers

Infostealer Status Main targets Common delivery Business model Current risk
Lumma / LummaC2 Recently disrupted, still highly relevant Browser credentials, cookies, wallets, files, system data Fake installers, malvertising, phishing, loaders, social engineering Malware-as-a-service Critical
RedLine Disrupted in Operation Magnus, historically dominant Browser credentials, cookies, wallets, application credentials Cracked software, phishing, fake installers, loaders Malware-as-a-service High historical and residual risk
Raccoon / RecordBreaker Intermittent activity and rebranding history Browser data, cookies, wallets, application data Cracked software, phishing, loaders Malware-as-a-service High when active
Vidar Long-running and still relevant Browsers, cookies, wallets, screenshots, system data Malvertising, loaders, fake software Sold or rented criminal tool High
StealC Fast-growing recent family Browsers, cookies, wallets, application credentials Loaders, phishing, fake installers Malware-as-a-service High
RisePro Fast-growing recent family Browser data, cookies, wallets, system data Loader ecosystems, fake software, phishing Malware-as-a-service High
Rhadamanthys Sophisticated, disrupted by Operation Endgame in 2025 Browsers, password managers, wallets, files, system data Phishing, loaders, fake installers Malware-as-a-service / criminal platform Critical
FormBook / XLoader Long-running Credentials, form data, keystrokes, screenshots Email phishing, attachments, malicious documents Sold criminal tool High
Agent Tesla Long-running Keystrokes, clipboard, credentials, screenshots Email phishing, attachments Commodity malware / paid tool High
Snake Keylogger Active commodity family Keystrokes, credentials, browser data, clipboard Phishing attachments, archives, scripts Commodity malware Medium to high
AZORult Older but influential Browser data, wallets, credentials Phishing, exploit kits historically, loaders Commodity malware Medium historical risk
Pony / Fareit Legacy classic stealer Credentials, FTP, email, browser data Phishing, botnets, loaders Commodity malware Medium historical risk
LokiBot Long-running Browser and application credentials Phishing, malicious attachments Commodity malware Medium to high
Mars Stealer AZORult-related lineage Browsers, wallets, 2FA extensions, files Fake software, cracked tools Commodity stealer Medium
Aurora Stealer More recent stealer Browsers, wallets, files, system data Fake software, loaders Commodity stealer Medium to high
Mystic Stealer MaaS-style modern stealer Browsers, wallets, credentials, files Phishing, fake installers Malware-as-a-service Medium to high
Meduza Stealer Modern commodity stealer Browsers, password managers, wallets Fake software, loaders Malware-as-a-service Medium to high
StrelaStealer Narrower focus Outlook and Thunderbird email credentials Email phishing, archive attachments Commodity stealer Medium to high for email compromise
Ducktail Specialized stealer Facebook Business accounts, browser data, cookies Social engineering, fake business files Specialized criminal tool High for ad-account fraud
NodeStealer Specialized social-account stealer Facebook, browser cookies, credentials Fake tools, social lures, malicious archives Specialized criminal tool High for social and ad fraud
FickerStealer Commodity family Browsers, wallets, application credentials Fake software, loaders Commodity malware Medium

This table groups families by practical risk rather than by strict code lineage. That approach is more useful for readers because defenders usually care about what a stealer does, how it arrives, and what business impact follows.

The data Windows stealers want most

The most valuable data type is browser session material. Passwords are useful, but cookies, tokens, and full browser profiles can be more powerful. A password may trigger multi-factor authentication. A valid session can sometimes place the attacker directly inside the account. This makes session theft one of the defining capabilities of modern stealers.

Browser data also gives attackers a map of the victim’s digital life. Saved passwords reveal services. Autofill data reveals names, addresses, phone numbers, and payment details. Browsing history reveals banks, SaaS tools, crypto exchanges, cloud consoles, social platforms, and internal systems. Cookies reveal active sessions. Extensions reveal password managers, crypto wallets, authentication tools, and business applications.

Crypto wallets are another major target. Many stealers search for wallet browser extensions, wallet desktop apps, seed phrase files, clipboard content, and local wallet databases. Some also monitor clipboard activity to replace copied wallet addresses. The financial value is immediate because crypto theft can be monetized quickly and often crosses borders easily.

Enterprise credentials are a rising priority. Modern stealers may collect VPN profiles, cloud CLI files, SSH keys, Kubernetes configurations, Git credentials, package manager tokens, FTP profiles, RDP data, email client credentials, and SaaS cookies. Microsoft’s reporting on the broader infostealer trend highlights growing interest in developer secrets, SSH keys, Kubernetes configs, AWS credentials, browser data, session data, and crypto wallets across modern campaigns.

Why stolen logs are so valuable

A stealer log is more than a password dump. It is a snapshot of a person, a device, and the accounts connected to that device. A single log can include the victim’s machine name, username, IP address, country, installed browsers, saved credentials, cookies, wallet files, screenshots, and application data. This gives criminals the context needed to decide how to monetize the infection.

For consumer victims, that may mean bank fraud, crypto theft, gaming account theft, identity theft, or social media takeover. For business victims, it may mean access to email, SaaS platforms, cloud dashboards, code repositories, customer systems, ad accounts, CRM tools, HR portals, or finance software. A contractor or employee using a personal device for work can expose corporate systems even when the original infection happens outside the corporate network.

This explains the connection between infostealers and ransomware. Ransomware affiliates need initial access. Stealer logs can provide that access through VPN credentials, remote desktop credentials, cloud sessions, email sessions, or single sign-on access. The buyer of the log can enter through identity rather than through malware exploitation. This is why identity teams, SOC teams, fraud teams, and incident response teams increasingly treat stealer logs as an early warning signal.

Distribution methods: how Windows stealers reach victims

The most common delivery pattern is social engineering. Attackers place malware where victims already look for software, documents, tools, or account help. Fake installers, cracked applications, game cheats, fake VPNs, fake AI tools, browser updates, productivity utilities, and PDF tools are common lures. Malicious search ads and SEO poisoning increase reach by placing attacker-controlled pages in front of users with high intent.

Phishing remains a major channel, especially for families such as Agent Tesla, FormBook, XLoader, Snake Keylogger, LokiBot, and StrelaStealer. These campaigns often use invoice themes, shipping notifications, purchase orders, payment reminders, scanned documents, or business correspondence. The attachment may be an archive, executable, script, ISO, Office document, or shortcut file.

Loader ecosystems also play a central role. A loader such as Amadey, SmokeLoader, PrivateLoader, HijackLoader, or another malware delivery platform can install a stealer after initial execution. This gives criminals flexibility. They can deploy a stealer to one victim, a RAT to another, and ransomware-related tooling to a third. Red Canary specifically identifies loader and lure ecosystems such as HijackLoader, MintsLoader, CypherIT, and paste-and-run lures as part of the 2025 stealer landscape.

Technical comparison: what defenders should compare

A useful technical comparison starts with the stealer’s collection scope. The first question is which browsers, wallets, applications, and credential stores the malware targets. The second is whether it steals cookies and session material. The third is whether it collects enterprise-grade secrets such as cloud credentials, VPN profiles, SSH keys, and developer tokens.

Persistence is another important dimension. Some stealers run once, collect data, and exit. Others establish persistence through registry run keys, scheduled tasks, startup folders, services, or dropped components. One-shot stealers can still cause severe damage because the value is in the stolen data. Persistent stealers increase the risk because they can collect fresh credentials after password resets.

Exfiltration method is also important. Telegram-based exfiltration is common in lower-cost tooling. Dedicated command-and-control panels suggest a more mature service. SMTP, FTP, Discord webhooks, and HTTP POST methods appear across different families. Network controls can help, but attackers often rotate infrastructure and use trusted platforms to blend in.

Anti-analysis capability separates commodity scripts from more mature malware-as-a-service platforms. Advanced stealers may check for sandboxes, virtual machines, debugging tools, security processes, geolocation, keyboard language, or analysis artifacts. They may use packing, encryption, process injection, staged payloads, or dynamic configuration. These features increase the time needed for analysis and detection engineering.

Business comparison: which stealers matter most

For business risk, the most important question is what an attacker can do with the stolen material. A family that steals only browser passwords creates risk. A family that steals passwords, cookies, VPN profiles, cloud keys, crypto wallets, screenshots, and files creates a much larger risk. A family that commonly appears in ransomware-adjacent intrusion chains deserves even higher priority.

The highest-risk Windows commodity stealers combine four traits. They are active or recently active. They collect browser sessions and broad credential types. They appear in large-scale distribution campaigns. They produce logs that are useful for downstream account takeover. Lumma, RedLine, Vidar, StealC, RisePro, and Rhadamanthys fit this profile in different ways.

Specialized stealers deserve attention too. StrelaStealer targets email clients, which makes it relevant for business email compromise. Ducktail and NodeStealer target Facebook and business accounts, which makes them highly relevant for advertising fraud and social media takeover. Agent Tesla and FormBook remain relevant because email phishing continues to reach businesses at scale.

Operational impact after infection

The impact of a Windows stealer infection continues after the malware file is removed. This is the central remediation challenge. Removing the executable from the endpoint addresses the malware process. It does not automatically invalidate stolen cookies, passwords, OAuth tokens, API keys, SSH keys, cloud credentials, or wallet files already in criminal hands.

A proper response starts by identifying the exposed identity, device, and accounts. The organization should reset passwords, revoke sessions, rotate tokens, review MFA devices, invalidate OAuth grants, check cloud access keys, review VPN and SSO logs, inspect mailbox rules, and search for suspicious logins. For developer workstations, the response should include GitHub tokens, package registry tokens, SSH keys, cloud CLI credentials, Kubernetes files, Docker credentials, and secrets stored in local config files.

The timing matters. Logs can be sold quickly, and buyers may act before the victim knows an infection occurred. This makes dark web and credential exposure monitoring valuable, but it also means organizations should build internal processes for rapid session revocation and identity containment.

Detection and prevention priorities

The most effective defensive posture combines endpoint, identity, browser, and user behavior controls. Endpoint detection should look for suspicious access to browser credential stores, mass reading of browser profile directories, unusual archive creation in temporary folders, unexpected connections to Telegram or unknown C2 infrastructure, suspicious PowerShell or script execution, and malware launched from user-writable paths.

Browser and identity defenses are equally important. Organizations should enforce phishing-resistant MFA where possible, reduce persistent sessions for sensitive applications, monitor impossible travel and unusual device fingerprints, and alert on session-cookie replay patterns. Password managers help reduce browser-saved passwords, but they also require strong configuration and monitoring because some stealers target password manager artifacts or browser extensions.

Application control can reduce risk from cracked software, unsigned executables, and unapproved installers. Least privilege reduces the amount of data available to malware. EDR coverage on contractor and BYOD devices is harder, so companies should treat unmanaged device access as an identity risk and apply stricter conditional access policies.

User education should focus on the actual lures people encounter. Generic advice about suspicious links is less effective than clear examples: fake CAPTCHA pages asking users to paste commands, sponsored search results for software downloads, cracked tools, fake browser updates, password-protected archives, and invoice attachments that launch scripts.

Comparison framework for future posts

The best way to compare Windows commodity stealers is to score each family across prevalence, capability breadth, enterprise impact, evasion, ease of criminal access, persistence, and remediation complexity. This creates a practical view for readers.

Dimension Low Medium High
Prevalence Rare or historical Seen periodically Common in current campaigns and log markets
Capability breadth Passwords only Passwords, cookies, wallets Full browser profiles, wallets, files, app secrets, cloud data
Enterprise impact Mostly consumer accounts Some business account exposure SaaS, VPN, cloud, developer, and email compromise potential
Evasion Basic script or packed executable Some obfuscation Active anti-analysis, frequent updates, mature infrastructure
Criminal accessibility Private or limited Sold in forums Broad MaaS access, affiliate ecosystem, active support
Persistence One-shot execution Basic persistence Durable access or paired with RAT/loader ecosystem
Remediation complexity Password reset Password reset plus session revocation Full token, session, endpoint, cloud, and identity response

This framework helps readers understand why two stealers with similar names can create very different levels of risk. A noisy one-shot stealer on a personal device still matters. A mature stealer on a developer workstation with cloud credentials can become a serious enterprise incident.

Conclusion

Windows commodity infostealers are a major engine of modern cybercrime because they convert endpoint infections into reusable identity assets. They are easy to distribute, easy to monetize, and valuable to many different criminal groups. Some buyers want bank accounts. Others want crypto wallets. Others want SaaS sessions, cloud credentials, advertising accounts, email inboxes, or ransomware access.

The most important shift is that infostealers have moved from simple password theft to full identity theft. A modern Windows stealer can capture the material needed to impersonate a user across personal, financial, social, and corporate systems. This makes the category relevant to SOC teams, fraud teams, threat intelligence teams, cloud security teams, and executives.

For defenders, the key lesson is straightforward. Treat every stealer infection as an identity incident, not only as a malware cleanup. The endpoint is the starting point. The real damage often lives in the accounts, sessions, tokens, and logs that leave the machine within minutes.

Ran Geva
Ran Geva
linkedin
Spread the news

Check your company's
exposed credentials

Enter your work email to instantly access a free account
and see your company’s exposed credentials.