Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Protection - The Dark Economy of Stolen Credentials: Inside ReliaQuest’s Infostealer Pipeline Report
Data Protection Data Loss Prevention Latest News News & Analysis Study & Research

The Dark Economy of Stolen Credentials: Inside ReliaQuest’s Infostealer Pipeline Report

Kirsten DoyleBy Kirsten DoyleJune 3, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
ReliaQuest Infostealer Pipeline Report
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The cybercrime landscape has entered a new era, one where a $2 stolen password can trigger a multimillion-dollar breach.  

According to ReliaQuest’s latest report, The Infostealer Pipeline: How Russian Market Fuels Credential-Based Attacks, the underground economy of stolen credentials is thriving, industrialized, and alarmingly easy to access. For organizations today, this isn’t just a threat—it’s a crisis of compromise. 

A $2 Price Tag on Your Network? 

At the heart of this ecosystem sits Russian Market, a dark web Automated Vending Cart (AVC) where threat actors can buy infostealer logs for less than the cost of a coffee. These logs contain sensitive data, credentials, cookies, credit card details, even crypto wallet info—extracted by information-stealing malware. And business is booming. 

In 2024 alone, ReliaQuest’s GreyMatter Digital Risk Protection (DRP) service raised over 136,000 alerts related to stolen credentials listed on Russian market. Fast forward to May 2025, and another 50,000 alerts have already been issued. This is proof that this isn’t a temporary surge but a sustained, industrialized trend. 

No sector is safe. From tech to telecom, every industry has been caught in the crosshairs. But some are hit harder than others. 

PSTS and Information Sectors 

ReliaQuest’s data shows that the professional, scientific, and technical services (PSTS) sector, along with the information industry, bore the brunt of credential exposure, accounting for 60% of all alerts in the reporting period. Why? Two reasons stand out: 

  1. Digital Dependence: These fields rely heavily on web-based research and online collaboration, which increases the chance of encountering drive-by downloads or malicious ads. 
  1. Complex Supply Chains: Employees receive emails from a wide range of senders, including unfamiliar sources, making spearphishing lures harder to detect. 

This makes them fertile ground for infostealer infections, and ripe targets for threat actors seeking low-effort, high-reward access points. 

Lumma’s Reign and What Comes Next 

While numerous infostealer malware families exist, Lumma (also known as LummaC2) dominated the Russian Market scene in late 2024, responsible for a whopping 92% of credential log alerts in Q4. Lumma’s success was due to its technical capabilities and deceptive tactics like fake CAPTCHA pages to infect systems. 

However, Lumma was taken down in May 2025, creating a power vacuum. Enter Acreed, a rising contender that’s already outpacing other established malware in Q1 2025. The game of malware king-of-the-hill continues, but the rules stay the same: infect, extract, and sell. 

The Attacker’s Playbook: Obfuscation and Persistence 

Infostealers are stealthy, persistent, and built for evasion. ReliaQuest’s report shows how they hide in writable directories like Temp, use obfuscated filenames, and “living-off-the-land” tactics to abuse legitimate system processes and fly under the radar. 

To maintain access, malefactors use popular persistence tactics such as registry edits, scheduled tasks, or planting files in startup folders. These prolong dwell time, increasing the amount of sensitive data they can harvest, and giving buyers more value for their $2 investment. 

The New Crown Jewels 

Cybercrooks are like pickpockets, they go where the crowds are. So as entities migrate workloads to the cloud, they follow. Credentials for cloud services, SaaS apps, and SSO systems have become prime real estate on dark marketplaces. According to the report: 

  • 61% of logs included SaaS credentials 
  • 77% included SSO credentials 

Why does this matter? Because a compromised SSO login isn’t only a foot in the door, it’s a skeleton key to a firm’s entire digital environment. 

Russian Market: Recycled But Relentless 

Despite its scale, a whopping 85% of Russian Market logs also appear on other platforms, proving that its value isn’t in its exclusivity but its ease of use and reliability. Its longevity, ultra-low pricing, and seamless buying experience make it an irresistible option for practiced threat actors and cybercrime newbies alike. 

Action Is Critical 

Credential theft has become a business model  supported by platforms like Russian Market and driven by malware-as-a-service. As the lines between amateur and advanced attackers blur, it’s no longer enough to “raise awareness.” Busineses need to act. 

That means they must prioritize identity and threat detection, harden cloud authentication mechanisms, and train employees in phishing resistance. They should also monitor the dark web for leaked credentials tied to their domain 

The pipeline is bursting, and the prices are affordable. On the flip side, the cost of compromise remains sky-high. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access
  • Kirsten Doyle
    Major US telecom providers debut C2 ISAC to counter AI-driven threats

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}