StealC

Introduced in early 2023, Stealc is an emerging MaaS (Malware as a Service) infostealer based on the Vidar, Raccoon, Mars and Redline stealers. Stealc focuses on stealing sensitive data from web browser files, crypto wallets (both browser- and desktop-based), as well as account data from apps including Outlook and Telegram, in addition to employee file […]

Redline

RedLine Stealer is malicious software that steals sensitive data from browsers, apps, and crypto wallets. This malware collects device information and can launch ransomware attacks. Operating as a remote access trojan, it exfiltrates data to hackers who sell it on dark web forums. Available as malware-as-a-service (MaaS), its affordability and effectiveness make it a widely […]

LummaC2

Lumma Stealer, also known as LummaC2, is a Russian related infostealer that emerged as a MaaS (Malware as a Service) in 2022. Lumma quickly became one of the most popular stealers thanks to its various ways of distribution and the difficulty to detect the malware once it has infected the device. In May of 2025, […]

Cyber Reconnaissance

Cyber reconnaissance is early information-gathering that determines how attackers prepare for intrusions, and how defenders prepare attacks.  Key Takeaways  Cyber reconnaissance is the first stage of the cyber kill chain to map assets, users and weaknesses.  Passive reconnaissance is based on public and other third‑party data, while active reconnaissance directly probes systems and is easier […]

Cross-Platform Identity Linking

Cross-platform identity linking is the process of connecting multiple online identities, accounts, and personas to the same underlying threat actor or group. It provides analysts with a full understanding of malicious activity spread across platforms, channels, and devices, turning isolated clues into a cohesive threat story. Key Takeaways Cross-platform identity linking connects disparate accounts, aliases, […]

Attack Surface Mapping

Attack surface mapping is the process of determining and visualizing the different ways an attacker could access your organization’s systems, data, and people. It transforms fragmented assets and exposures into a comprehensive picture of how your organization can be reached and exploited. Key Takeaways Attack surface mapping builds a view for digital, physical, and social […]

ULPs

What Are Username and Login Pairs (ULPs)? Username and login pairs, often referred to as ULPs, are stolen account credentials captured directly from real user activity. As per the name, a ULP is made up of two parts: a username and password, both generally taken from an actual login session. In many cases, the ULP […]

Combo Lists

What Are Combo Lists? A combo list is a file that contains large numbers of username and password pairs. A single combo list may contain thousands or even millions of credentials, collected from various sources. Attackers use these files to test login combinations across online services. Most combo lists originate from past data exposures. Cybercriminals […]

Data Breach

What Is a Data Breach? A data breach is when someone accesses information on a computer, in a cloud platform, on a database or in a shared drive that they were not supposed to access. Type of data could include customer details, login credentials, credit card numbers, internal files, medical records or anything else a […]

Infostealers

What is an Infostealer?  Infostealer malware is designed to infiltrate a device and exfiltrate data such as login credentials, session cookies, financial details, and personally identifiable information, typically to a server controlled by attackers. But unlike ransomware, which announces itself, a breach by an infostealer is often invisible to the victim, since the malware’s primary […]