← Blog

January 12, 2026

How info-stealer logs end up for sale

When info-stealer malware runs on a machine, it doesn't target one account — it grabs everything the browser has saved: passwords, cookies, autofill data, sometimes cryptocurrency wallets. Everything it finds gets bundled into a single file, usually called a "log," identified by that one infected machine.

From one machine to thousands

A single log is rarely valuable on its own. What makes stealer logs a real market is volume: operators run the malware at scale, through cracked software and fake installers, and collect thousands of logs at a time. Those get bundled and traded — sometimes sold outright, sometimes leaked for free to build reputation on criminal forums and Telegram channels.

This is why a report can show more than one exposure for the same identifier: the same person's credentials can appear in several different logs if they were infected more than once, or if the same log gets re-packaged and re-distributed by different sellers.

Why occurrence counts matter

A credential that shows up once in one log is a different risk profile than one that shows up across a dozen. That's the reasoning behind the occurrence counts on every credential in a report — how many times it appears in the exposure you're looking at, and how many times globally across everything we've indexed. A high global count is a signal the password itself is circulating widely, independent of who it belonged to.