Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar 2.0, StealC, AMOS/MacSync/Poseidon/Odyssey) — Threadlinqs Intelligence
As of 2026-07-25, Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar 2.0, StealC, AMOS/MacSync/Poseidon/Odyssey) is a high-severity malware threat attributed to Infostealer MaaS Operators (Multiple (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 36 indicators of compromise.
Threat ID: TL-2026-1693 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Infostealer MaaS Operators (Multiple · Russia · FINANCIAL
A cross-platform Malware-as-a-Service (MaaS) infostealer ecosystem — LummaC2, Rhadamanthys, Vidar 2.0, ACRStealer/Acreed and StealC on Windows, plus Atomic macOS Stealer (AMOS), MacSync, Poseidon and
Stealer logs have become the upstream access-broker commodity of the cybercrime economy: infostealer malware silently exfiltrates browser-stored passwords, active session cookies/authentication tokens (which bypass MFA entirely when replayed), autofill and payment-card data, cryptocurrency wallet files and seed phrases, hardware/device fingerprints, and VPN/FTP/SaaS application tokens (Slack, Discord, GitHub, cloud consoles) from infected endpoints, then packages the harvest into structured 'logs' for resale.
On Windows, the dominant families through 2025-2026 are LummaC2 (Lumma Stealer), Rhadamanthys, Vidar 2.0, ACRStealer (rebranded/succeeded by Acreed), and StealC/StealC v2 — all operated as subscription-based MaaS platforms with affiliate programs, update bulletins, and dedicated customer support channels on underground forums and Telegram. On macOS, Atomic macOS Stealer (AMOS) dominated through most of 2025 before a temporary disappearance in October 2025 and a February 2026 return; its codebase was forked by former AMOS developer 'Rodrigo4' into Poseidon Stealer, which was itself rebranded and upgraded into Odyssey Stealer, while MacSync (formerly Mac.C) emerged as the primary commodity macOS stealer by year-end 2025.
Delivery increasingly relies on social-engineering execution rather than exploiting software vulnerabilities: ClickFix fake-CAPTCHA pages that trick victims into pasting and running attacker-supplied commands, malvertising, trojanized software/crack downloads, fake Homebrew or crypto-wallet installers on macOS, and abuse of signed system binaries (mshta.exe proxying obfuscated remote JavaScript). LummaC2 has also been observed using 'EtherHiding' — hosting or resolving second-stage payload locations via Binance Smart Chain smart contracts — while Vidar uses a Telegram/Mastodon 'dead-drop resolver' pattern to fetch its live C2 IP, both techniques designed to survive conventional domain/IP takedown actions.
Law enforcement has twice struck at the ecosystem's core infrastructure without eliminating it. Operation Endgame's May 2025 action (DOJ, Europol EC3, Japan's JC3, and Microsoft's Digital Crimes Unit) seized over 2,300 domains tied to LummaC2, which had infected roughly 400,000 Windows machines between March 16 and May 16, 2025 alone; LummaC2 only partially recovered market share by early 2026. Operation Endgame's third phase (10-14 November 2025) seized more than 1,000 servers and 20 domains tied to Rhadamanthys, VenomRAT, and the Elysium botnet — Rhadamanthys alone had generated 525,303 unique infections across 226 countries between March and November 2025 — yet activity simply redistributed to Vidar 2.0 and other surviving families. This 'hydra' pattern, combined with 1.8 billion credentials stolen in 2025, an 84% year-over-year increase in phishing-delivered stealers (IBM X-Force), 54% of ransomware victims having had domain credentials already present in stealer logs before their attack (Verizon 2025 DBIR), and 77% of Russian Market logs containing SSO tokens (ReliaQuest), establishes stealer logs as a durable, self-healing access-broker commodity feeding downstream account-takeover fraud and ransomware intrusions.
Target sectors: cryptocurrency, financial services, technology saas, all sectors opportunistic mass-distribution
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 36 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1082, T1518.001, T1217, T1012, T1566.001, T1566.002, T1195, T1204, T1204.002, T1059.001