1 link tagged with all of: ransomware + credential-theft + malware-as-a-service + cybercrime
Click any tag below to further narrow down your results
Links
In 2025, infostealer malware infected over 11 million devices and exposed 3.3 billion credentials, browser artifacts, session tokens, and system metadata. Sold as malware-as-a-service for as little as $60 a month, strains like Vidar and Lumma use sandbox detection and obfuscation to evade defenses, harvesting passwords, cookies, crypto keys, and more. Attackers then resell the data or use the stolen credentials to gain undetected access and deploy ransomware.
- Infostealer malware hit over 11.1 million devices in 2025, exposing 3.3 billion credentials and session tokens on underground markets, with kits renting for as little as $60/month.
- Vidar exploded in early 2026 to 73% of infections (up from 4th place), while 2025's leader Lumma collapsed to about 1.1%.
- Stolen data (passwords, cookies, session tokens, crypto keys, system metadata) is packaged into "stealer logs" and sold on to other criminal groups, who use it to bypass defenses and deploy ransomware.
- Victims typically have no idea they're compromised until ransom demands appear or their credentials surface for sale, since the malware evades detection via sandbox checks and obfuscation.