Global Threat Intelligence Report:
2026 Mid Year Edition
Data, insights, and key takeaways on the most impactful threats of 2026—from AI and infostealers to ransomware and vulnerabilities.
Information-Stealing Malware Threats
Flashpoint’s proprietary infostealer data and intelligence, as detailed in this section, is derived from extensive monitoring of over thirty active infostealer families, illicit online marketplaces, dedicated Telegram channels, and specialized bot shops where stealer logs and related services are traded. The intelligence presented here reflects activity observed from January 1, 2026 to June 30, 2026.
Infostealers Overview
January 2026 – June 2026
7.4M
Infected Hosts
& Devices
1.7B
Stolen Credentials
(Sourced by Infostealers)
What is the Current Scale of Global Infostealer Infections?
Flashpoint’s intelligence recorded 7.4M infected hosts and devices globally during the first half of 2026, representing a 27% period-over-period increase in information-stealing malware operations. This massive malware footprint acted as an industrial-scale harvesting engine, extracting a staggering 1.7B stolen credentials directly from compromised systems over the six-month window. The sheer volume of these metrics confirms that cybercriminals have systematically shifted their primary focus away from traditional technical network entry, relying instead on harvesting authentic user identities to bypass enterprise perimeters.
This high-velocity infection rate was sustained by a highly specialized commodity malware market. Vidar, StealC, and Lumma—including its various clones such as Remus—maintained their dominance as the most prolific infostealer families by volume of infected devices. The vast quantities of credentials siphoned by these specific families provide the foundational raw material fueling the broader underground access economy, driving the initial access trends seen throughout the rest of the 2026 threat landscape.
What Are the Defining Infostealer Trends and Insights in 2026?
AI Transforms Stolen Logs into High-Density Identity Harvesting Engines
The infostealer landscape in H1 2026 continues to transition from human-led credential gathering campaigns into a fully automated threat ecosystem. Flashpoint Primary Source Collections document over 22M AI-related illicit discussions across underground forums, signaling an aggressive shift from basic AI experimentation to the deployment of malicious agentic AI frameworks on local infrastructure.
These systems do not require constant human oversight; instead, they function as autonomous credential processing engines capable of ingestion and orchestration at machine speed. This evolution redefines the lifecycle of a breach. Threat networks are now connecting these malicious agents directly to raw log supply chains. Once infostealer families harvest data, these systems immediately ingest records, parsing out high-value metadata, and automatically initiate parallel credential stuffing and active session testing across thousands of environments simultaneously.
Stolen Credentials Allow Attackers to Bypass Defenses and Simply Log In
Flashpoint continues to observe threat actors pivoting away from overly technical entry methods. While leveraging exploits and zero-day vulnerabilities are still common initial access vectors, attackers are recognizing that it is operationally faster and cheaper to simply login to victim systems, rather than developing techniques to penetrate network perimeters and firewalls.
Leveraging stolen identity data allows threat actors to bypass complex edge defenses entirely. They simply input valid information and passwords to authenticate into enterprise VPNs, cloud instances, webmail, and corporate software-as-a-service (SaaS) platforms while mimicking legitimate, authorized employees. This method turns human trust into a highly scalable, weaponizable attack surface.
What Are the Key Takeaways for Infostealer Threats?
1
Identity Replaces Technical Exploits as the Primary Corporate Attack Surface
The harvesting of 1.7 billion stolen credentials across 7.4 million infected devices in a single six-month window confirms that digital identity has become the primary exploit vector for modern adversaries. This massive inventory of valid credentials has fundamentally flipped the mechanics of a security breach. Because attackers can easily buy or extract valid usernames and passwords to bypass complex edge perimeters, they no longer need to rely on developing sophisticated, technical zero-day exploits to force their way into a network—instead, they are simply logging in.
2
Subscription Malware-as-a-Service (MaaS) Pipelines Feed the Global Access Economy
The widespread footprint of compromised hosts is heavily sustained by an interconnected, highly professionalized Malware-as-a-Service (MaaS) marketplace. Commodity infostealer families—led by volume giants Vidar, StealC, and Lumma (including its clones, such as Remus)—are openly rented to threat actors on dark web forums and Telegram channels. Because these strains are engineered with advanced anti-analysis and in-memory execution capabilities, they quietly dump corporate browser caches and active session tokens, providing the raw material that fuels downstream Initial Access Brokers and ransomware syndicates.
What Are the Best Strategies for Proactive Infostealer Defense?
Establish External Visibility Into Primary Underground Infostealer Supply Chains
Gain direct visibility into the primary source underground ecosystems where stolen identity first appears and is traded—including illicit online marketplaces, dedicated Telegram channels, automated bot shops, and active malware repositories. Deploy continuous external threat monitoring that maps an organization’s core domains, SaaS interdependencies, and third-party vendor spaces directly against these primary source collections. Catching exposed logs at this early junction allows defenders to identify compromised accounts within days of initial infection, closing security gaps before downstream threat networks can leverage them for corporate intrusions.
Operationalize Log Parsing and Enrichment to Dissect Host and Session Metadata
Leverage advanced intelligence solutions and automated services for rigorous log parsing and enrichment. The enrichment framework should dissect every incoming log file to extract and tag vital technical components beyond standard usernames and passwords—specifically capturing active browser session cookies, host operating system types, installed enterprise applications, local IP ranges, and distinct malware family attributions (such as Vidar, StealC, or Lumma). This structured metadata enables threat intelligence and incident response teams to instantly filter out false positives and identify high-value corporate assets facing active session-hijacking threats.
Enforce Continuous Token Revocation and Phishing-Resistant Identity Controls
Transition enterprise identity infrastructure to fully phishing-resistant authentication models, such as hardware security keys, and completely disable credential caching within local web browsers via centralized group policies. Concurrently, configure the enterprise identity provider to enforce continuous access evaluation and short-lived session lifetimes. If the automated log enrichment feed flags an active corporate account or session token circulating in an underground log dump, an automated orchestration playbook should immediately revoke all active endpoint tokens, terminate the user’s active cloud sessions, and force an absolute credential reset.