A weekly report on infostealer activity from July 20-27, 2026, highlights the immense scale of credential theft operations, with 101,326 domains compromised in a single week. The campaigns led to the infection of 10,025 machines and 5,026 Android devices. The Acreed infostealer was the most prevalent malware family, accounting for 21,319 compromised machines. Another key finding was that Windows Defender was the most frequently encountered antivirus product on infected systems, suggesting that its default configurations are not sufficient to stop these threats. The Lumma stealer also played a significant role in the weekly compromises.
The report underscores the continuous and high-volume nature of infostealer malware campaigns. These threats are designed to steal sensitive information from infected devices, including browser cookies, saved passwords, cryptocurrency wallet data, and system information. This stolen data is then aggregated and sold on underground markets or used to facilitate more significant attacks like ransomware or corporate espionage.
Infostealers are typically distributed through phishing, malicious ads (malvertising), or cracked software. Once executed, they target specific data stores on the victim's machine.
T1204.002 - User Execution: Malicious File.T1560 - Archive Collected Data).T1041 - Exfiltration Over C2 Channel).The finding that Windows Defender was the most common AV on infected systems (10,227 instances) is significant. It suggests that the stealers are either effectively obfuscated to avoid signature-based detection or are using techniques to bypass behavioral protections. The fact that 925 machines had no AV at all highlights ongoing gaps in basic security hygiene.
The primary impact of infostealer malware is the theft of credentials and session cookies. For individuals, this can lead to financial loss and identity theft. For organizations, the impact is more severe. When an employee's machine is compromised, their corporate credentials and VPN access tokens can be stolen. This provides threat actors with a foothold inside the corporate network (T1078 - Valid Accounts), which is often the first step in a major ransomware attack or data breach. The sale of these 'initial access' logs on dark web markets is a thriving industry that fuels the broader cybercrime ecosystem.
No specific Indicators of Compromise (IOCs) were provided in the source articles.
To hunt for infostealer activity, security teams should look for the following:
file_path%APPDATA%\..\Local\Google\Chrome\User Data\Default\Login Dataprocess_namewscript.exe, cscript.exenetwork_traffic_patternLogin Data, Local State files) or the Windows credential manager. This is a high-fidelity indicator of credential theft.M1032 - Multi-factor Authentication.M1017 - User Training.M1028 - Operating System Configuration.Enforcing MFA can prevent stolen passwords from being used directly, though it may not stop session cookie theft.
Training users to identify and avoid phishing and malicious downloads is a key preventative control.
Use web filters to block access to known malicious domains and categories commonly used to host malware, such as newly registered domains.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.