Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar 2.0, StealC, AMOS/MacSync/Poseidon/Odyssey)

Stealer Logs (TL-2026-1693), also tracked as Stealer Logs Underground Economy, is a high-severity malware campaign, first published 2026-07-25. It is attributed to Infostealer MaaS Operators (Russia) with medium confidence, affects Multiple (cross-platform MaaS operators) Windows endpoints — browsers, maps to 44 MITRE ATT&CK techniques (T1005, T1012, T1027), and is covered by 9 detection rules and 36 indicators of compromise.

Key facts for TL-2026-1693

Threat ID
TL-2026-1693
Also known as
Stealer Logs Underground Economy, Infostealer-as-a-Service Ecosystem
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-25
Last reviewed
2026-07-25
Attribution
Infostealer MaaS Operators
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
cryptocurrency, financial services, technology saas, all sectors opportunistic mass-distribution
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
36

Malware and tooling in Stealer Logs

Malware and tooling: ACRStealer / Acreed, AMOS, LummaC2 (Lumma Stealer), MacSync (formerly Mac.C), Odyssey Stealer, Poseidon Stealer, Rhadamanthys, Stealc, Vidar 2.0

A cross-platform Malware-as-a-Service (MaaS) infostealer ecosystem — LummaC2, Rhadamanthys, Vidar 2.0, ACRStealer/Acreed and StealC on Windows, plus Atomic macOS Stealer (AMOS), MacSync, Poseidon and Odyssey on macOS — harvests browser credentials, session cookies/SSO tokens, autofill and payment data, cryptocurrency wallets, and VPN/FTP/cloud application tokens, packaging them into 'stealer logs' resold on Russian Market, Telegram, and dark web forums. Two major law-enforcement disruptions in 2025 (LummaC2 in May, Rhadamanthys in November) failed to eliminate the ecosystem, with market share consistently migrating to surviving or new families within days to weeks.

How Stealer Logs works

Stealer logs have become the upstream access-broker commodity of the cybercrime economy: infostealer malware silently exfiltrates browser-stored passwords, active session cookies/authentication tokens (which bypass MFA entirely when replayed), autofill and payment-card data, cryptocurrency wallet files and seed phrases, hardware/device fingerprints, and VPN/FTP/SaaS application tokens (Slack, Discord, GitHub, cloud consoles) from infected endpoints, then packages the harvest into structured 'logs' for resale.

On Windows, the dominant families through 2025-2026 are LummaC2 (Lumma Stealer), Rhadamanthys, Vidar 2.0, ACRStealer (rebranded/succeeded by Acreed), and StealC/StealC v2 — all operated as subscription-based MaaS platforms with affiliate programs, update bulletins, and dedicated customer support channels on underground forums and Telegram. On macOS, Atomic macOS Stealer (AMOS) dominated through most of 2025 before a temporary disappearance in October 2025 and a February 2026 return; its codebase was forked by former AMOS developer 'Rodrigo4' into Poseidon Stealer, which was itself rebranded and upgraded into Odyssey Stealer, while MacSync (formerly Mac.C) emerged as the primary commodity macOS stealer by year-end 2025.

Delivery increasingly relies on social-engineering execution rather than exploiting software vulnerabilities: ClickFix fake-CAPTCHA pages that trick victims into pasting and running attacker-supplied commands, malvertising, trojanized software/crack downloads, fake Homebrew or crypto-wallet installers on macOS, and abuse of signed system binaries (mshta.exe proxying obfuscated remote JavaScript). LummaC2 has also been observed using 'EtherHiding' — hosting or resolving second-stage payload locations via Binance Smart Chain smart contracts — while Vidar uses a Telegram/Mastodon 'dead-drop resolver' pattern to fetch its live C2 IP, both techniques designed to survive conventional domain/IP takedown actions.

Law enforcement has twice struck at the ecosystem's core infrastructure without eliminating it. Operation Endgame's May 2025 action (DOJ, Europol EC3, Japan's JC3, and Microsoft's Digital Crimes Unit) seized over 2,300 domains tied to LummaC2, which had infected roughly 400,000 Windows machines between March 16 and May 16, 2025 alone; LummaC2 only partially recovered market share by early 2026. Operation Endgame's third phase (10-14 November 2025) seized more than 1,000 servers and 20 domains tied to Rhadamanthys, VenomRAT, and the Elysium botnet — Rhadamanthys alone had generated 525,303 unique infections across 226 countries between March and November 2025 — yet activity simply redistributed to Vidar 2.0 and other surviving families. This 'hydra' pattern, combined with 1.8 billion credentials stolen in 2025, an 84% year-over-year increase in phishing-delivered stealers (IBM X-Force), 54% of ransomware victims having had domain credentials already present in stealer logs before their attack (Verizon 2025 DBIR), and 77% of Russian Market logs containing SSO tokens (ReliaQuest), establishes stealer logs as a durable, self-healing access-broker commodity feeding downstream account-takeover fraud and ransomware intrusions.

MITRE ATT&CK techniques used in TL-2026-1693

Collection

T1005 Data from Local System; T1074.001 Local Data Staging; T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection

Discovery

T1012 Query Registry; T1082 System Information Discovery; T1217 Browser Information Discovery; T1518.001 Security Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.013 Encrypted/Encoded File; T1036.008 Masquerade File Type; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1218.007 Msiexec; T1218.015 Electron Applications; T1497.001 System Checks; T1564.003 Hidden Window; T1574.001 DLL; T1620 Reflective Code Loading; T1622 Debugger Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 PowerShell; T1059.006 Python; T1059.010 AutoHotKey & AutoIT; T1204 User Execution; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer; T1573.002 Asymmetric Cryptography

Persistence

T1176 Software Extensions; T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1195 Supply Chain Compromise; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

Credential Access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers

defense-impairment

T1553.002 Code Signing; T1685 Disable or Modify Tools

stealth

T1574.001 DLL

Resource Development

T1583.001 Domains; T1583.003 Virtual Private Server

Affected products and versions in Stealer Logs

  • Multiple (cross-platform MaaS operators) — Windows endpoints — browsers, cloud/SaaS sessions, cryptocurrency wallets
    Vulnerable versions: Chromium- and Firefox-based browsers on Windows 10/11 endpoints lacking behavioral EDR
    Fixed in: Not applicable — not a software vulnerability; mitigated via credential rotation, session invalidation, and endpoint/behavioral detection
  • Apple — macOS endpoints — Keychain, browsers, cryptocurrency wallets
    Vulnerable versions: macOS systems targeted via fake installers, ClickFix pages, and malvertising
    Fixed in: Not applicable — not a software vulnerability

Remediation for Stealer Logs

Immediate actions

  • Rotate all credentials and invalidate active browser session cookies/tokens for any host suspected of stealer-log exposure
  • Enforce phishing-resistant MFA (FIDO2/WebAuthn) to neutralize stolen-password value and reduce session-cookie replay risk
  • Block known stealer C2 IPs/domains (see threat_iocs) at DNS, proxy, and perimeter firewall layers
  • Hunt for mshta.exe spawning PowerShell or making network connections, and for ClickFix-style clipboard-paste/Run-dialog execution patterns

Workarounds

  • Disable or restrict AutoHotkey, AutoIT, and unsigned script interpreters on endpoints where not business-required
  • Restrict outbound access to hosting ASN ranges flagged on the Spamhaus DROP list

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to bulk browser-credential-store access, keychain/LSASS access, and dead-drop C2 lookups (Telegram/Mastodon/blockchain)
  • Implement continuous dark-web and stealer-log monitoring (Russian Market, Telegram channels) keyed to the organization's domains
  • Adopt short-lived, device-bound session tokens to blunt the resale value of stolen session cookies
  • Restrict unmanaged browser-extension installation and enforce application allow-listing to reduce infostealer persistence surface

Timeline of Stealer Logs

  • LummaC2 (Lumma Stealer) first advertised on underground forums as a Malware-as-a-Service platform by the threat actor 'Shamel'.
  • StealC infostealer first observed in the wild, built atop code from Vidar, Raccoon, Mars, and RedLine stealers, and gains traction as a dark-web MaaS offering.
  • Atomic macOS Stealer (AMOS) discovered; developers begin selling it as MaaS on hacker forums and Telegram.
  • FBI-led seizure of Genesis Market infrastructure triggers a 670% surge in Russian Market listing activity as displaced buyers migrate to the surviving marketplace.
  • Poseidon Stealer developer 'Rodrigo4' (former AMOS developer) sells the Poseidon codebase, later resurfacing to maintain its successor, Odyssey Stealer.
  • StealC-V2 registered, adding PowerShell/MSI payload-delivery loader modules and server-side Chromium credential decryption.
  • Microsoft observes a cluster of compromised websites using EtherHiding (Binance Smart Chain smart contracts) combined with ClickFix fake-CAPTCHA social engineering to deliver Lumma Stealer.
  • Operation Endgame — DOJ, Europol's EC3, Japan's JC3, and Microsoft's Digital Crimes Unit — begins a coordinated takedown of LummaC2 infrastructure.
  • Microsoft's Digital Crimes Unit completes seizure of over 2,300 domains tied to LummaC2, which had infected roughly 400,000 Windows PCs worldwide between March 16 and May 16, 2025.
  • Rhadamanthys emerges as the leading infostealer family through summer 2025, absorbing market share vacated by the LummaC2 takedown within days to weeks.
  • Atomic macOS Stealer (AMOS) disappears from active distribution.
  • Operation Endgame's third phase, coordinated from Europol's headquarters in The Hague (10-14 November 2025), dismantles Rhadamanthys, VenomRAT, and the Elysium botnet, seizing over 1,000 servers and 20 domains; 525,303 unique Rhadamanthys infections had been identified across 226 countries between March and November 2025.
  • MacSync (formerly Mac.C) emerges as the primary commodity macOS infostealer by year-end 2025.
  • Vidar 2.0 becomes the most widely used infostealer among threat actors per Flashpoint's 2026 Global Threat Intelligence Report, absorbing activity displaced by the Rhadamanthys takedown.
  • AMOS returns to distribution after its October 2025 disappearance; AhnLab ASEC's February 2026 trend data lists LummaC2 (partially recovered), Vidar, ACRStealer/Acreed, and StealC as the top four distributed Windows infostealer families.

Sources cited for Stealer Logs

Threats related to Stealer Logs

Detection coverage for TL-2026-1693

As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1693 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats