Infostealers Turn Millions of Devices Into Credential Theft Machines
This report details a significant increase in the use of infostealers as a primary method for attackers to steal credentials and gain unauthorized access to networks. Over 11.1 million devices were infected in 2025, resulting in the circulation of over 3.3 billion credentials and other sensitive data. The rise of ‘stealers’ like Lumma and Vidar, often delivered via malware-as-a-service, highlights the evolving threat landscape and the vulnerability of organizations relying solely on traditional security measures.
The cybersecurity landscape has shifted dramatically, with infostealers emerging as the dominant vector for credential theft. Attackers are increasingly bypassing traditional security defenses by leveraging these tools to directly acquire user credentials, offering a faster, less detectable, and more effective approach than brute-force attacks or exploiting vulnerabilities. Flashpoint’s analysis reveals a massive surge in infostealer infections, with over 11.1 million devices compromised in 2025, leading to the proliferation of billions of stolen credentials across illicit marketplaces. These credentials are then used to gain access to valuable data within targeted organizations, often undetected by existing security controls.
The report identifies several key trends within the infostealer ecosystem. The availability of these tools, often through malware-as-a-service (MaaS) models, has made them accessible to a wide range of attackers, including Iranian hackers. Stealers like Lumma, Acreed, Rhadamanthys, Vidar, and StealC have dominated the market, with Vidar experiencing a dramatic surge in popularity in early 2026. These tools employ sophisticated techniques, such as string encryption and obfuscation, to evade detection by security software, and they actively gather a broad range of data, including credentials, browser cookies, and system metadata. This data is then packaged and sold to criminal groups, who frequently use it to deploy ransomware attacks.
Furthermore, the report emphasizes the ease of use and effectiveness of infostealers, often facilitated through social engineering attacks. The consequences of this trend are severe, as stolen credentials can be directly used to trigger ransomware deployments, highlighting the critical need for organizations to implement robust identity and access management (IAM) solutions and continuously monitor for credential compromise.