Infostealer malware infected 7.4 million devices in the first half of 2026 and harvested about 1.7 billion credentials, according to threat intelligence firm Flashpoint — a 27% rise in infected hosts over the preceding six months. The figures land alongside the same firm’s earlier count of 11.1 million devices infected over the previous year, and roughly 3.3 billion stolen credentials, session cookies, cloud tokens and other identity artifacts circulating in illicit markets.

Those numbers describe a market, not a malware family. Stolen logins have become a commodity input to other crimes — ransomware, business email compromise, cloud account takeover — sold and resold at prices low enough that direct network intrusion is often the more expensive option.

What the reports actually count

Flashpoint’s June 2026 report, Identity Is the New Attack Surface, is the fuller of the two. It identifies more than 30 active infostealer strains across underground ecosystems and says the firm’s own credential database exceeds 48 billion records, with more than a billion tied specifically to infostealer activity. It also notes that 4.2% of exposed credential sets include browser cookies capable of supporting session hijacking.

That last figure is small in percentage terms and large in consequence, because a valid session cookie represents an already-authenticated session. An attacker replaying one does not need the password, and does not need to defeat multi-factor authentication — the authentication already happened.

“Attackers have increasingly shifted to a simpler strategy: logging in with valid identities,” Ian Gray, Flashpoint’s vice president of intelligence, said. He described the economics as the driver: “Threat actors no longer need to compromise a network directly when billions of credentials, session cookies, and authentication artifacts are already circulating in underground ecosystems.”

Flashpoint’s midyear update, published August 17, 2026, added a note on industrialization: the log supply chain is increasingly automated, with what the firm called “autonomous credential processing engines capable of ingestion and orchestration at machine speed” wired directly to raw stealer output, enabling immediate credential testing across many environments at once.

A volatile market with a stable product

The vendors behind individual stealers churn quickly, usually because of takedowns and arrests rather than competition on merit. Flashpoint’s ranking of the five most prolific strains by infected hosts in 2025 — Lumma, Acreed, Rhadamanthys, Vidar and StealC — had already been reshuffled by early 2026.

As SecurityWeek reported in June 2026, Vidar accounted for 73% of infected hosts in early 2026 after ranking fourth the year before, while Lumma — the previous leader — collapsed to 1.1%. Access to the malware itself is sold as a service from around $60 a month.

What the strains collect is broadly the same regardless of which one is ascendant: saved website passwords, enterprise credentials for VPN, remote desktop and webmail, SaaS and cloud platform logins, browser cookies and active session tokens, cryptocurrency wallet data, payment card details and system metadata. Distribution is conventional social engineering aimed at people on ordinary desktops and laptops — frequently personal machines that also hold work credentials.

From a personal laptop to a corporate breach

The link between commodity infections and serious incidents shows up in incident response data. Coveware’s Q2 2026 report lists phishing and social engineering as the leading route into extortion cases it handled, with remote access compromise second and compromised credentials rising as a standalone vector even as vulnerability exploitation declined.

Verizon’s 2026 Data Breach Investigations Report, published May 19, 2026, offers a useful counterweight: it found that 31% of breaches now begin with software vulnerabilities, overtaking stolen passwords as the single most common initial access route. Credential abuse has not stopped mattering — it has been joined at the top rather than displaced, and the two feed each other, since stolen credentials are what turn an exploited edge device into sustained access.

The lag is the operational problem. Flashpoint says logs from some infections can be collected and parsed within one to two days, meaning a credential can be circulating in a marketplace long before anyone in the affected organization has reason to look. SecurityWeek’s summary of the position was unsparing: most victims are unaware they are victims until they are breached, and threat intelligence visibility “doesn’t prevent you being a victim, it merely confirms that you have become one.”

What vendors are now recommending

The defensive advice has shifted from password hygiene toward identity monitoring and session management. Flashpoint’s recommendations, drawn from its June report, are representative of where the industry has landed:

  • Monitor the underground sources where stolen identity data first appears — forums, marketplaces and messaging channels — rather than relying only on aggregated breach notification feeds.
  • Continuously identify exposed credentials tied to corporate domains, and treat discovery as an incident trigger rather than a report line item.
  • When credentials surface, reset them and invalidate active sessions. Rotating a password without terminating existing sessions leaves the stolen cookie working.
  • Investigate the infected device, not just the account — one compromised machine usually yields credentials for many services.
  • Review authentication activity on affected accounts for signs the credentials were already used.
  • Treat employee and partner identities as part of the attack surface to be inventoried and managed, alongside servers and applications.

Two structural controls sit behind all of that. Phishing-resistant authentication — hardware security keys and passkeys bound to a device and origin — removes the value of a stolen password outright, which is why enterprise rollouts accelerated through 2025 and 2026. Shorter session lifetimes and re-authentication for sensitive actions reduce the useful life of a stolen cookie.

Neither is cheap to deploy across a large workforce, and neither helps with credentials already sitting in a marketplace. But the direction of the 2026 data is consistent: as long as a valid login is the cheapest way into an organization, the identity layer is where the contest is being decided.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *