● Data Breaches

Infostealer Logs Drive Massive Cloud Breaches as Credentials Replace Exploits

July 24, 2026 · snewle
Infostealer Logs Drive Massive Cloud Breaches as Credentials Replace Exploits

Infostealer malware has emerged as the dominant initial-access commodity in the cybercrime economy, with threat actors now purchasing their way into enterprise networks rather than exploiting vulnerabilities. Infostealer logs containing valid credentials, session cookies, and SSO tokens harvested from infected endpoints are being replayed directly against cloud consoles, SaaS platforms, and VPN gateways. Cisco Talos Q1 2026 incident-response data confirms that phishing and credential-based access have overtaken exploit-driven intrusions as the top initial-access vector, with the majority of credentials originating from stealer logs.

How Did the Snowflake Breach Demonstrate This Threat?

The 2024 Snowflake breach serves as the definitive example of this attack pipeline. Threat actor UNC5537, also known as Scattered Spider or ShinyHunters, did not exploit any Snowflake vulnerability. Instead, the group used credentials harvested by infostealer malware from Snowflake customer employees, with some infections dating back to 2023. Passwords were found stored in unsecured spreadsheets and password managers, and critically, none of the compromised accounts had multi-factor authentication enabled.

The campaign ultimately affected at least 165 organizations including AT&T, Ticketmaster, Santander Bank, Neiman Marcus, and Advance Auto Parts. The breach exposed over 50 billion AT&T call records and drove extortion demands exceeding $2 million. UNC5537 deployed a custom exfiltration toolkit called FROSTBITE to automate bulk data scraping once inside Snowflake instances.

A more recent example emerged in January 2026 with the Zestix/Sentap campaign, which used credentials harvested by RedLine, Lumma, and Vidar to breach corporate accounts on ShareFile, Nextcloud, and OwnCloud. The attackers exfiltrated defense engineering blueprints, healthcare records, and legal and financial archives without exploiting any software vulnerability.

What Is the Scale of Enterprise Credential Exposure?

Flare’s 2026 State of Enterprise Infostealer Exposure report reveals that 2.05 million infostealer logs exposed enterprise identity credentials in 2025 alone. Enterprise identity exposure in infected logs rose from roughly 6% in early 2024 to nearly 16% by 2026. Significantly, 79% of those enterprise logs contained Microsoft-linked SSO credentials, and approximately 1.17 million logs contained both credentials and live session cookies, enabling immediate access that bypasses MFA entirely through session replay.

How Does the Infostealer-to-Breach Pipeline Operate?

The attack chain runs through five distinct stages operated by specialized actors in the cybercrime supply chain. First, infection occurs when a user executes the stealer payload through social engineering lures. The malware then collects browser-stored passwords, session cookies, autofill data, crypto wallets, and system fingerprints, packaging them into a ZIP archive per victim device. These logs are exfiltrated, frequently via the Telegram Bot API, which has become the dominant command-and-control channel.

Logs are then sold in bulk on automated marketplaces like Russian Market, 2easy, STYX, and DarkForums for as little as $1 to $50 per log. Initial Access Brokers filter these logs for enterprise VPN, SSO, or cloud-admin credentials, verify the access still works, and resell it privately to ransomware affiliates for $500 to $5,000 depending on privilege level and sector. Credentials typically move from theft to underground listing within 48 hours, and ransomware affiliates have been observed weaponizing purchased access within 48 hours of listing.

Which Malware Families Are Driving This Trend?

Lumma Stealer has emerged as the market leader, evading detection while targeting passwords, cookies, and crypto wallets, now frequently paired with CastleLoader. Vidar remains stubbornly persistent as a durable malware-as-a-service family. StealC, believed linked to Vidar developers, was actively disrupted by Microsoft’s Digital Crimes Unit in June 2026. RedLine, the pioneer of the MaaS stealer model, was crippled by Operation Magnus in late 2024 but its legacy footprint still surfaces in old logs. CastleLoader-delivered Lumma campaigns have reached over 100,000 potential victims with hundreds of associated malicious domains observed across DNS telemetry.

What Industries Face the Greatest Risk?

Cyfirma’s June 2026 ransomware tracking shows Professional Goods & Services as the most targeted sector with 45 incidents, followed by Manufacturing with 35, Healthcare with 25, Real Estate & Construction with 19, Consumer Goods & Services with 18, Finance with 16, and Government & Civic with 14. Manufacturing has held the top targeted-industry position for four consecutive years according to IBM X-Force data, while healthcare carries the highest average breach cost at $7.42 million.

Source: Cybersecurity News