Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Enterprise Applications Carry 4.31x More Critical and High Vulnerabili

August 18, 2026

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

August 18, 2026

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw

August 18, 2026
Facebook X (Twitter) Instagram
Tuesday, August 18
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Infostealers Harvest 1.7 Billion Credentials in Six Months
News

Infostealers Harvest 1.7 Billion Credentials in Six Months

Team-CWDBy Team-CWDAugust 17, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security researchers recorded 7.4 million devices infected with infostealer malware in the first half of 2026, a 27% increase from the previous six months, according to Flashpoint data.

The threat intelligence company revealed the news in its 2026 Global Threat Intelligence Report: Midyear Edition, which features information collected from deep and dark web forums, illicit marketplaces, encrypted channels, and threat actor-linked infrastructure and ecosystems.

In total, it claimed that hackers harvested 1.7 billion credentials via infostealer malware between January and June 2026, with Vidar, StealC and Lumma the top three most prolific infostealer variants.

The infostealer landscape has now transformed into a fully automated threat ecosystem, Flashpoint claimed.

“These systems do not require constant human oversight; instead, they function as autonomous credential processing engines capable of ingestion and orchestration at machine speed. This evolution redefines the lifecycle of a breach,” the report explained.

“Threat networks are now connecting these malicious agents directly to raw log supply chains. Once infostealer families harvest data, these systems immediately ingest records, parsing out high-value metadata, and automatically initiate parallel credential stuffing and active session testing across thousands of environments simultaneously.”

Read more on infostealers: Novel macOS Infostealer AmnesiaStealer Spread via ClickFix

Although the figures describe the prominent role of identity as an attack surface, the report also pointed to the continued proliferation of software vulnerabilities.

Flashpoint tracked 21,667 vulnerability disclosures over the period: an 8% increased from the previous six months. Nearly one in five (19%) flaws was accompanied by public or functional exploit code.

However, of this number, only a small percentage were actually exploited. Flashpoint’s Known Exploited Vulnerabilities (KEV) catalog tracked 239 flaws undergoing active, in-the-wild exploitation during H1 2026. That’s 191% more than the 82 flaws identified by the federal CISA KEV list, Flashpoint claimed.

The vendor also asserted that its team was able to isolate 6808 vulnerabilities for customers before they were even published by the National Vulnerability Database (NVD).

Malicious AI Activity Surges Underground

The underground markets that support the trade in both infostealers and software vulnerabilities are being shaped by the rapid rise of AI threats.

Over the period, Flashpoint captured over 22 million posts related to malicious use of AI on illicit forums and closed-chat channels.

With commoditized access to open source AI, many threat actors are deploying tooling locally, meaning they don’t need to rely on public underground networks or specially built deployment services, the report claimed.

“However, for those that do still need these services, cybercrime-trained AI offerings remain overwhelmingly concentrated within rapid-delivery messaging platforms and open-source infrastructure,” it continued.

“These platforms, such as Telegram, are commonly utilized by illicit communities, followed by Reddit, GitHub, and Pastebin.”

Such channels have effectively become a distribution layer for malware, social engineering scripts and more, Flashpoint noted.

Elsewhere in the report, Flashpoint counted 6256 ransomware victims in the first six months of this year – a 45% increase from the previous six months. This trend is being driven by automation, low-cost initial access and a mature ransomware-as-a-service (RaaS) ecosystem.

However, as has been noted elsewhere, fewer organizations are paying their extorters.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Next Article Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks
Team-CWD
  • Website

Related Posts

News

Enterprise Applications Carry 4.31x More Critical and High Vulnerabili

August 18, 2026
News

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

August 18, 2026
News

Cyber Incident Disrupts Student Services at UT San Antonio

August 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

AI-powered financial scams swamp social media

September 11, 2025

A phishing attack that doesn’t steal your password

June 15, 2026

Chronology of a Skype attack

February 5, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.