
Imagine you could obtain access to any Fortune 100 company for $10 or less, even for free. Terrifying thought, isn't it? Or exciting, depends on which side of the cybersecurity barricade are you on. Well, that's basically the state of things today. Welcome to the infostealer garden of low-hanging fruit.
Over the last few years, the problem has grown bigger and bigger, and just now we are slowly learning its full destructive potential. In this article, we will describe how the whole cybercriminal ecosystem is working, the ways various threat actors are exploiting data originating from it, and most importantly, what you can do about it.
Let's start with what infostealer malware actually is. As the name suggests, it's a malware that... steals data. Depending on the specific type, the information it extracts might differ a little bit, but most of them will try to extract the following:


And more and more stuff, as the malware developers add additional features over time. As you can imagine, you don't want this kind of information to be leaked on the internet, for everyone to see. Neither you want credentials to your organization's internal systems being compromised this way. Yet that's exactly what's happening each and every day to thousands of users.
You don't have to be particularly tech-savvy to spread infostealer malware, nor rich to obtain valuable data stolen with it by other threat actors. Let's take a look at how the whole ecosystem works.
An ongoing trend on the dark side of the internet is specialization. While in the past, it was more common for one individual or group to take care of the whole process, nowadays the path to your company assets is paved by many different competing threat actors, that specialize in just one part of the "industry" and will happily provide their services to anyone willing to pay, in a true free-market spirit.
An example of the "old way" might be the famous Zeus banking malware. It was developed and spread by the same group of people. Stolen data have been exploited by them also, and all proceeds from this criminal enterprise went back to them. And there was no way for you, a petty cybercriminal, to make money with their results or even more so, buy the malware itself, so that you could spread it on your own.
Well, the market evolved. While there are still actors operating completely on their own, the bar for entering the world of stealing other people's data is much lower. You, even as an individual, can join the ranks of the cybercrime startup industry. The following positions are now open:
You will be responsible for developing the small, yet important piece of software on which the rest of the "industry" often relies: the malware dropper, or loader if you please.
While the infostealer malware file itself tends to be rather big because it contains lots of functionality, the malware dropper has only one goal: bypass the antivirus and create a way for other actors to download their malicious code to the device.
An example of such a dropper might be the Smoke Loader, operating since 2011 and still adding new functionality to this day. Dropper/loader developers either exploit accesses obtained with their software themselves or resell them through various darknet forums to others, or both. In the darknet lingo, an infected computer is known as "install" and there are many "installs services" claiming to provide you with a way to spread your own stuff (be it infostealer, cryptominers or other malicious code) through them. Usually, they will assure you that they sell the "install" to your hands only, but from our experience, it's often not the case, as the "installs service" operators will try to monetize it to the max.

One such service, InstallsKey, will sell the infected (with their own dropper) computers to you for less than a dollar to 10 bucks, depending on the locality. That's not exactly dirty cheap, but if you know what you are doing, you will get your "investment" back rather quickly.
The engine of the "industry". You'll need some years of experience with programming and preferably a good knowledge of how the Windows OS works.
Infostealer malware, often loaded through some kind of dropper as described above, extracts all kinds of potentially valuable info and sends a package containing it to the attacker through some kind of communication channel. A non-comprehensive list of commercially available infostealer malware:
And there are many, many others. Prices of subscriptions range from dozens to lower hundreds of dollars per month.

Usually, you will receive a "builder" application, with which you can create an .exe file that suits your needs, often bypassing most common AV solutions (therefore partially covering the functionality droppers provide). Depending on the type, you'll receive your victim's data through a web panel (either self-hosted or provided to you) or Telegram.

Bypassing antivirus for the price of a few beers? Not a problem, crypter developers will allow you to do just that, so that you can focus on... well, whatever it is you are up to.

A crypter is a piece of code that will pack your very evil .exe file in a way that most common AV solutions won't notice it. Both droppers and infostealers sometimes already include some kind of AV bypassing, but crypter will add an additional layer so that you can achieve even more sinister results.
Spreading infostealer en-masse is a difficult task for a lonely hacker, so it's better to team up with other like-minded individuals! That's what traffer teams (or tрафферы) are for. Organizing through forums and (partially automated) Telegram channels/bots, they will provide you with a turnkey solution to infect non-suspecting users of the internet looking for that Adobe crack or free Fortnite skins. For a percentage of crypto you manage to steal, they will provide you with everything you need, from undetectable stealer to a manual on creating fake YouTube tutorials, that are often used for spreading.
Are you a people person? Then you might consider the career of the traffer team manager. You'll just have to glue together a crypte/infostealer malware of your choice and create a friendly Telegram bot to onboard new workers. There's some competition, so you should work on your PR and possibly give the workers a bigger share of the cake than they'll get elsewhere. Still, if you manage to convince enough people to work for you, it's a pretty good deal.

Perfect entry-level position. If you are willing to learn new stuff and have no moral barriers.
Select the traffer team with the best conditions, onboard using the Telegram bot and you are ready to go. Your job will mostly consist of creating fake YouTube tutorials or scam pages, that'll convince your victims to download the infostealer malware build provided to you by the traffer team.

Depending on the team you choose, you might receive up to 90% of the crypto you manage to steal, and as a bonus, sometimes even the logs themselves (after they are "worked out" for popular monetization methods by your managers). You can either try some other, less usual monetization methods, or just resell them further, or share them for free to obtain respect from your evil peers.
Obtain logs from public sources and present them as "unique", "private" and your own. Profit. That's how it usually works. Log cloud is a service that'll provide you with a stream of more or less "fresh" logs on a daily basis (for a fee, of course), usually in the form of a Telegram channel or a continuously updated MEGA.nz storage.

These logs have usually been through many hands and are "worked out" for the most popular requests, but still may contain a golden nugget if you know what you are looking for (also known as a "unique request").
HackedList.io automatically monitors hundreds of Telegram channels. The observed duplicity rate is rather high:

It's quantity over quality, but well, there's strength in quantity too. Some log clouds accumulated terabytes of data over the years.
Terabytes of compressed logs means even more terabytes of raw material. And if the only thing you are looking for is a pair of username and password for that specific site you want to obtain access to, you don't even need the whole log package. So a separate segment of the "market" evolved: resellers of .txt files in the format of URL:login:password, created out of the standard log packages. Instead of terabytes, it's just gigabytes now and you can easily search through it with standard utilities like grep.

Otherwise, url:log:pass resellers operate exactly the same way as log cloud operators, except they have to store and deal with less data. Other services, in the form of both websites and Telegram bots exist, that allow you to search through them, so you don't even have to know how to use grep or where to obtain this kind of logs.

Want actually unique and private logs? Visit an automated log market website! It'll be much more expensive (yes, the log cloud offers are too good to be true), but you have a chance that you are the first one (well, second or third one, but that's still fair) to have that log.

For $10 or less, threat actors can obtain all kinds of accesses to such places, with the added benefit that such a log will be just theirs, at least for some time. In the past, there have been three such big marketplaces operating simultaneously. After Genesis.Market was taken down in an international law enforcement operation, and 2Easy marketplace development was abandoned, there's just for major player on the field: the infamous Russian Market. To this day (13-07-2024), it has 7,266,780 records available for sale, and an unknown, but surely a large number of logs has been already sold on the platform.
Looking for valid and valuable information in the terabytes of data available through log clouds or on automated marketplaces is like looking for a needle in a haystack. But if you manage to find it, it can score you a big sum of money. So that's where initial access brokers step in. They look for (still) valid credentials obtained by infostealer infections and use them to establish footholds in compromised networks. Then, they sell these to anyone willing to pay, often threat actors like ransomware gangs.
Here's an example from a well-known darknet forum:

A quick check on HackedList.io reveals, that the OWA access most probably originates from an infostealer breach:

There are ransomware gangs, APTs, skilled initial access brokers and then there are, of course, script kiddies. The bored youth looking for quick cash or just ways to wreak havoc on the internet.
Publicly (or for a low price) available data from infostealer infections provide them with a great tool to cause lots of damage with little knowledge. You don't have to know any programming, because somebody else already wrote the stealer. You don't have to know how to spread it, because somebody else already did. You don't even have to manually try the obtained credentials to verify if they work, because, yes, you guessed it, somebody else already created a tool to do it for you. So you just pick the low-hanging fruit and cause damage.

And no, we are not talking about overtaking Minecraft or Discord servers. LAPSUS$, a hacker group of teenagers aged 16 to 21, managed to steal 780 gigabytes of data from the video game publishing giant, Electronic Arts. The same group was behind the Uber hack, where they got in through a compromised account of an external contractor. In both cases, the root cause was an infostealer infection.
To sum it up, here's a fancy diagram:

HackedList.io focuses on all kinds of log dealers and darknet marketplaces and can alert you before the bad guys labeled as attackers in the infographics above can take advantage.
Here are some statistics:

The bad news is, that with such a high infection rate, there's a big probability that your organization was already compromised - the bigger your organization is, the bigger the probability.
The good news is, that you can check for free if it happened, and we at HackedList.io offer solutions to help protect your assets - just enter your domain here: