Threat Actors With Stealer Malwares Processing Millions of Credentials a Day
The ecosystem surrounding stealer malware has transformed into a complex criminal enterprise, capable of processing hundreds of millions of credentials daily. This development poses significant threats to digital security, as criminal networks establish…
The ecosystem surrounding stealer malware has transformed into a complex criminal enterprise, capable of processing hundreds of millions of credentials daily. This development poses significant threats to digital security, as criminal networks establish intricate systems for managing and distributing stolen authentication data.
Recent investigations have revealed the extensive scale of these operations. Security researchers have monitored a single Telegram account processing up to 50 million credentials within a 24-hour period. Telegram and similar messaging platforms have become primary channels for distributing stolen data, serving as marketplaces where data is exchanged among criminal entities.
The criminal network operates through a tiered structure:
Primary Sellers: Manage main operations and maintain both public and private channels for distributing stealer logs. Aggregators: Collect logs from various sources and redistribute them, often providing search capabilities for specific sites. Traffers: Collaborate with primary sellers to spread malware, sometimes operating their own channels to showcase their effectiveness.
Security analysts from Synthient identified this structure, aiming to aid victims by monitoring platforms and building systems to ingest shared data.
Recent investigations have revealed the extensive scale of these operations.
Threat actors utilize various credential formats depending on the malware family and distribution method:
ComboList: Uses delimiters like colons, semicolons, or pipes to separate email addresses and passwords. URL-Login-Password (ULP): Follows URL-Login-Password conventions. Stealer Logs: Contain structured data with labeled fields.
ComboList
email: password email; password email|password
ULP
url:login:password url|login|password
Aggregators face challenges consolidating stolen credentials due to inconsistencies in data formats. This complexity is exacerbated when primary sellers password-protect their archives to maintain control over the data.
Pricing models for access to stolen credentials range from weekly subscriptions at 60 dollars to lifetime access for 600 dollars. Analysis of major operations shows staggering volumes of credential flow, with systems processing up to 600 million credentials in a single day.
The technical hurdles in parsing and processing these credentials require advanced systems capable of handling different formats effectively.
Based on reporting by Cyber Security News.
