Infostealer Logs: The Catalyst Behind Massive Cloud Data Breaches

Infostealer malware has emerged as a pivotal tool in the cybercriminal arsenal, supplanting traditional phishing and exploit-based methods as the primary means of gaining unauthorized access to enterprise systems. By harvesting sensitive data such as usernames, passwords, session cookies, and Single Sign-On (SSO) tokens from compromised devices, attackers can infiltrate cloud services, Software as a Service (SaaS) platforms, and Virtual Private Network (VPN) gateways without the need for sophisticated exploits.

Recent incident-response data from Cisco Talos indicates that credential-based access, predominantly derived from infostealer logs, has surpassed exploit-driven intrusions as the leading initial access vector. This shift underscores the growing reliance on stolen credentials within the cybercrime ecosystem.

From Single Infection to Massive Breach

The 2024 Snowflake breach serves as a stark illustration of this trend. The threat actor group UNC5537, also known as Scattered Spider or ShinyHunters, leveraged credentials obtained through infostealer malware infections dating back to 2023. These credentials, often stored insecurely in spreadsheets and password managers, lacked multi-factor authentication (MFA), allowing attackers to access Snowflake customer accounts directly. The breach impacted at least 165 organizations, including AT&T, Ticketmaster, Santander Bank, Neiman Marcus, and Advance Auto Parts, exposing over 50 billion AT&T call records and leading to extortion demands exceeding $2 million. Once inside the Snowflake instances, UNC5537 utilized a custom exfiltration toolkit named FROSTBITE to automate large-scale data extraction.

Similarly, in January 2026, the Zestix/Sentap campaign exploited credentials harvested by infostealer variants such as RedLine, Lumma, and Vidar to compromise corporate accounts on cloud file-sharing platforms like ShareFile, Nextcloud, and OwnCloud. This campaign resulted in the exfiltration of sensitive data, including defense engineering blueprints, healthcare records, and legal and financial documents. Notably, these breaches did not involve exploiting software vulnerabilities but rather capitalized on stolen credentials and the absence of MFA.

The Infostealer-to-Breach Pipeline

The process by which infostealer malware facilitates large-scale breaches involves several distinct stages, each often managed by specialized actors within the cybercrime supply chain:

  1. Infection: A user, typically on a personal or unmanaged device, inadvertently executes the infostealer payload through deceptive means such as phishing emails or malicious downloads.
  2. Collection: The malware extracts browser-stored passwords, session cookies, autofill data, cryptocurrency wallets, and system information, compiling them into a compressed archive known as a “log” for each infected device.
  3. Exfiltration: The collected logs are transmitted to the malware operator, often via resilient and cost-effective channels like the Telegram Bot API, which blends into regular network traffic.
  4. Bulk Sale: These logs are then sold in large quantities on automated underground marketplaces such as Russian Market, 2easy, STYX, and DarkForums, sometimes for as little as $1 per log.
  5. Exploitation: Cybercriminals purchase these logs to gain unauthorized access to corporate systems, leading to data breaches, financial fraud, and other malicious activities.

Flare’s 2026 State of Enterprise Infostealer Exposure report highlights the scale of this issue, revealing that 2.05 million infostealer logs containing enterprise credentials were exposed in 2025 alone. The proportion of enterprise identity credentials found in these logs increased from approximately 6% in early 2024 to nearly 16% by 2026. Alarmingly, 79% of these enterprise logs contained Microsoft-linked SSO credentials, and about 1.17 million logs included both credentials and active session cookies, enabling immediate access that circumvents MFA through session replay attacks.

To mitigate the risks associated with infostealer malware, organizations should implement comprehensive security measures, including enforcing multi-factor authentication across all access points, conducting regular security awareness training for employees, and deploying advanced endpoint detection and response solutions. Additionally, monitoring for compromised credentials on dark web marketplaces can provide early warning signs of potential breaches, allowing for proactive remediation efforts.

The evolving threat landscape underscores the necessity for organizations to adapt their security strategies to address the growing prevalence of infostealer malware. By understanding the mechanisms through which these threats operate and implementing robust defenses, enterprises can better protect their sensitive data and maintain the integrity of their systems.