Information-Stealing Malware Threats

Flashpoint’s proprietary infostealer data and intelligence, as detailed in this section, is derived from extensive monitoring of over thirty active infostealer families, illicit online marketplaces, dedicated Telegram channels, and specialized bot shops where stealer logs and related services are traded. The intelligence presented here reflects activity observed from January 1, 2026 to June 30, 2026.

Infostealers Overview

January 2026 – June 2026

Infected Hosts
& Devices

Stolen Credentials
(Sourced by Infostealers)

What is the Current Scale of Global Infostealer Infections?

Flashpoint’s intelligence recorded 7.4M infected hosts and devices globally during the first half of 2026, representing a 27% period-over-period increase in information-stealing malware operations. This massive malware footprint acted as an industrial-scale harvesting engine, extracting a staggering 1.7B stolen credentials directly from compromised systems over the six-month window. The sheer volume of these metrics confirms that cybercriminals have systematically shifted their primary focus away from traditional technical network entry, relying instead on harvesting authentic user identities to bypass enterprise perimeters.

This high-velocity infection rate was sustained by a highly specialized commodity malware market. Vidar, StealC, and Lumma—including its various clones such as Remus—maintained their dominance as the most prolific infostealer families by volume of infected devices. The vast quantities of credentials siphoned by these specific families provide the foundational raw material fueling the broader underground access economy, driving the initial access trends seen throughout the rest of the 2026 threat landscape.

What Are the Defining Infostealer Trends and Insights in 2026?

AI Transforms Stolen Logs into High-Density Identity Harvesting Engines


The infostealer landscape in H1 2026 continues to transition from human-led credential gathering campaigns into a fully automated threat ecosystem. Flashpoint Primary Source Collections document over 22M AI-related illicit discussions across underground forums, signaling an aggressive shift from basic AI experimentation to the deployment of malicious agentic AI frameworks on local infrastructure.

These systems do not require constant human oversight; instead, they function as autonomous credential processing engines capable of ingestion and orchestration at machine speed. This evolution redefines the lifecycle of a breach. Threat networks are now connecting these malicious agents directly to raw log supply chains. Once infostealer families harvest data, these systems immediately ingest records, parsing out high-value metadata, and automatically initiate parallel credential stuffing and active session testing across thousands of environments simultaneously.



Stolen Credentials Allow Attackers to Bypass Defenses and Simply Log In


Flashpoint continues to observe threat actors pivoting away from overly technical entry methods. While leveraging exploits and zero-day vulnerabilities are still common initial access vectors, attackers are recognizing that it is operationally faster and cheaper to simply login to victim systems, rather than developing techniques to penetrate network perimeters and firewalls.

Leveraging stolen identity data allows threat actors to bypass complex edge defenses entirely. They simply input valid information and passwords to authenticate into enterprise VPNs, cloud instances, webmail, and corporate software-as-a-service (SaaS) platforms while mimicking legitimate, authorized employees. This method turns human trust into a highly scalable, weaponizable attack surface.

What Are the Key Takeaways for Infostealer Threats?

Identity Replaces Technical Exploits as the Primary Corporate Attack Surface

The harvesting of 1.7 billion stolen credentials across 7.4 million infected devices in a single six-month window confirms that digital identity has become the primary exploit vector for modern adversaries. This massive inventory of valid credentials has fundamentally flipped the mechanics of a security breach. Because attackers can easily buy or extract valid usernames and passwords to bypass complex edge perimeters, they no longer need to rely on developing sophisticated, technical zero-day exploits to force their way into a network—instead, they are simply logging in.

Subscription Malware-as-a-Service (MaaS) Pipelines Feed the Global Access Economy


The widespread footprint of compromised hosts is heavily sustained by an interconnected, highly professionalized Malware-as-a-Service (MaaS) marketplace. Commodity infostealer families—led by volume giants Vidar, StealC, and Lumma (including its clones, such as Remus)—are openly rented to threat actors on dark web forums and Telegram channels. Because these strains are engineered with advanced anti-analysis and in-memory execution capabilities, they quietly dump corporate browser caches and active session tokens, providing the raw material that fuels downstream Initial Access Brokers and ransomware syndicates.

Additional Resources