Infostealer Infections Explode to 74 Million Devices as Automated Cybercrime Enters a New Era

Listen to this Post

Featured Image

A New Warning From the Underground

The cybercrime economy is entering a dangerous phase in which stealing a password is no longer the end of an attack—it can be the beginning of an automated compromise chain. New threat intelligence data cited in the original report suggests that 7.4 million devices were infected with infostealer malware during the first half of 2026, representing a 27% increase compared with the preceding six months.

The significance goes far beyond the infection count. Infostealers are becoming part of a broader criminal infrastructure in which stolen credentials, browser sessions, cookies, tokens, personal information and corporate access can be collected, processed and monetized with increasingly little human intervention.

Flashpoint’s broader 2026 research supports this direction, describing a threat landscape in which identity, malware, vulnerabilities and infrastructure are converging into a single attack ecosystem. Its published annual report says more than 11.1 million machines were infected with infostealers during 2025, generating approximately 3.3 billion compromised credentials and cloud tokens.

The Main Story: Identity Has Become the New Battlefield

The original report highlights research attributed to

According to the supplied figures, attackers harvested approximately 1.7 billion credentials through infostealer malware between January and June 2026. Vidar, StealC and Lumma are identified as the three most prolific families during this period.

The numbers illustrate an uncomfortable reality: attackers increasingly do not need to defeat sophisticated security controls directly. They can simply acquire legitimate-looking credentials and attempt to enter through the front door.

From Malware Infection to Criminal Supply Chain

Infostealers were once primarily viewed as relatively straightforward malware designed to steal information from infected computers. That description is becoming dangerously incomplete.

Modern infostealer operations can generate detailed collections of credentials, browser information, authentication artifacts, cryptocurrency wallet information, cookies and other data that can be resold or immediately used.

The stolen information can become a commodity inside underground markets. One criminal operation infects the victim, another acquires the stolen logs, another specializes in credential attacks, and another monetizes compromised accounts.

This division of labor resembles a supply chain.

Machine-Speed Credential Abuse Changes Everything

Flashpoint describes this evolution as an increasingly automated ecosystem in which stolen information can be ingested and processed at machine speed.

Instead of an attacker manually opening thousands of stolen logs, automated systems can categorize information, identify valuable accounts and prioritize credentials associated with attractive targets.

That dramatically changes the economics of cybercrime.

A criminal group does not necessarily need hundreds of employees manually examining stolen data. Automation can perform repetitive discovery and validation tasks at a scale that humans cannot match.

Why Stolen Cookies Can Be More Dangerous Than Passwords

A password is valuable, but an authenticated browser session can sometimes be even more immediately useful.

Session cookies and authentication tokens may allow criminals to inherit an already-authenticated state. Depending on the application and its security architecture, this can undermine defenses that were designed primarily around passwords.

This is one reason identity protection has become such an important part of modern cybersecurity.

Flashpoint’s own 2026 research describes this transition as a shift from “breaking in” to “logging in,” emphasizing how compromised identities and cloud tokens can become the primary route into organizations.

Vidar, StealC and Lumma Remain Major Names

The original article identifies Vidar, StealC and Lumma as the leading infostealer families in the first half of 2026.

These names matter because they represent more than individual malware samples. Successful infostealer families operate inside an ecosystem involving distribution channels, malware developers, affiliates, stolen-data markets and buyers.

The result is an industrialized model of credential theft.

Vulnerabilities Are Rising Too

Infostealers are only one part of the problem.

The supplied report says Flashpoint tracked 21,667 vulnerability disclosures during the first half of 2026, an increase of approximately 8% from the preceding six months.

Nearly one in five vulnerabilities reportedly had public or functional exploit code.

That creates another major problem for defenders: organizations are not only dealing with more vulnerabilities, but attackers can increasingly obtain the technical information needed to weaponize them.

The Most Dangerous Vulnerabilities Are Not Necessarily the Most Numerous

Thousands of vulnerabilities can be disclosed in a single reporting period, but only a fraction will become actively exploited threats.

That distinction is critical.

Security teams cannot realistically treat every vulnerability as equally urgent. The practical challenge is determining which weaknesses are exposed, exploitable and relevant to the organization’s technology stack.

Flashpoint says its Known Exploited Vulnerabilities tracking identified 239 vulnerabilities undergoing active exploitation during the first half of 2026, compared with 82 entries in the federal CISA KEV list cited by the report.

The difference demonstrates why organizations increasingly require multiple intelligence sources rather than relying on a single vulnerability catalog.

Vulnerability Management Is Becoming a Race Against Time

The traditional vulnerability-management cycle was relatively straightforward: discover a vulnerability, assess it, develop a patch, deploy the patch and verify remediation.

That model becomes much harder when exploitation begins shortly after disclosure.

Flashpoint’s broader 2026 research says the gap between vulnerability discovery and mass exploitation is shrinking dramatically, including cases where exploitation can occur within roughly 24 hours of discovery.

For security teams, speed is becoming a defensive capability.

The Hidden Value of Pre-Disclosure Intelligence

The supplied article also claims Flashpoint identified 6,808 vulnerabilities for customers before they were published by the National Vulnerability Database.

If accurate, this represents an important shift in vulnerability management.

The traditional model waits for public disclosure before organizations begin understanding a vulnerability. Intelligence gathered from underground activity, researchers and other primary sources can potentially provide an earlier warning.

Early warning can mean additional time to investigate affected systems, apply mitigations or prepare defensive controls.

AI Is Becoming Part of the Criminal Infrastructure

The report also describes a dramatic increase in malicious discussions involving artificial intelligence.

According to the supplied figures, Flashpoint captured more than 22 million posts related to malicious AI use across illicit forums and closed-chat channels during the reporting period.

The important development is not simply that criminals are talking about AI.

It is that AI is increasingly being integrated into existing criminal workflows.

From AI Experiments to Automated Operations

Flashpoint’s published 2026 research describes a broader transition from generative AI experimentation toward agentic frameworks capable of performing portions of an attack lifecycle autonomously.

This distinction matters.

A chatbot that writes a phishing message is useful, but it still requires a human to operate it.

An automated system that identifies targets, generates customized content, rotates infrastructure, evaluates responses and adjusts its strategy represents a substantially different threat model.

Underground Platforms Are Becoming Distribution Networks

The original report identifies Telegram, Reddit, GitHub and Pastebin among platforms used by criminal communities for distributing or discussing malicious tools and content.

These services are not inherently criminal.

The problem is that legitimate infrastructure can also become useful to attackers because it provides scale, accessibility and familiarity.

A malicious campaign does not necessarily need a dedicated criminal hosting platform when legitimate services can be abused as part of its distribution or communication chain.

The Ransomware Problem Is Growing Too

Infostealers and vulnerability exploitation are occurring alongside continued ransomware activity.

The supplied figures put the number of ransomware victims during the first six months of 2026 at 6,256, representing a 45% increase from the preceding six months.

Flashpoint’s broader annual research similarly identifies ransomware as part of a rapidly professionalizing ecosystem and reported 53% growth during 2025.

Ransomware Does Not Always Need Encryption Anymore

One of the most important changes in ransomware is the declining importance of encryption alone.

Attackers can steal data, compromise identities, threaten public disclosure and exploit privileged access without necessarily depending on a traditional encryption payload.

This makes ransomware increasingly resemble an identity and extortion problem rather than simply a file-encryption problem.

Fewer Victims Are Willing to Pay

The original article notes that fewer organizations are paying their extortionists.

That development could eventually weaken some ransomware economics, but it does not automatically eliminate the threat.

Attackers can compensate by increasing victim volume, reducing operational costs, stealing more sensitive information or targeting organizations where downtime carries enormous financial consequences.

The Real Story Is the Convergence

The most important lesson from the data is not any single number.

It is the convergence between infostealers, stolen identities, vulnerabilities, AI automation and ransomware.

An infostealer can obtain credentials.

Those credentials can provide initial access.

A vulnerability can provide privilege escalation or additional access.

Automation can accelerate reconnaissance.

AI can help generate social-engineering content.

Ransomware operators can then use the resulting access for extortion.

These are no longer isolated threats.

They are components of one increasingly connected criminal economy.

Deep Analysis

Why Infostealers Are So Effective

Infostealers exploit one of the weakest points in many security architectures: the endpoint where users interact with browsers, applications and authentication systems.

A perfectly patched server does not necessarily protect an organization if an employee’s authenticated session is stolen from a compromised workstation.

This is why endpoint security, identity security and application security must increasingly be treated as interconnected layers.

The Attack Chain in Practical Terms

A simplified defensive model looks like this:

Initial Infection

Infostealer Execution

Credential / Cookie / Token Collection

Log Processing

Criminal Marketplace

Credential Validation

Account Takeover

Privilege Escalation

Data Theft / Extortion

The critical observation is that the malware infection is only the first stage.

The eventual damage may happen somewhere completely different.

Defensive Log Hunting

Security teams should investigate unusual authentication activity, especially when a legitimate account suddenly behaves differently from its normal pattern.

For example, defenders can examine authentication logs for impossible travel, unfamiliar devices, unusual user agents and abnormal session behavior.

A basic Linux search might look like:

grep -Ei "failed|invalid|authentication|login" /var/log/auth.log

For systems using journalctl, defenders can inspect authentication-related events with:

journalctl --since "24 hours ago" | grep -Ei "authentication|failed|invalid|login"

These commands are only starting points. Production environments should use centralized logging and SIEM correlation rather than relying exclusively on local log searches.

Windows Authentication Investigation

Windows defenders can begin investigating suspicious authentication activity through PowerShell and event logs:

Get-WinEvent -FilterHashtable @{
LogName='Security'
Id=4624,4625
} -MaxEvents 100

Event ID 4624 generally represents a successful logon, while 4625 represents a failed logon.

The value comes from correlating these events with source addresses, account names, logon types, device information and normal user behavior.

Search for Suspicious Processes

Endpoint telemetry should also be examined for unexpected processes launched from user-writable locations.

A basic PowerShell inventory can help identify running processes:

Get-Process |
Sort-Object CPU -Descending |
Select-Object -First 30 Name, Id, CPU

This is not an infostealer detector by itself.

Its purpose is to demonstrate the kind of host visibility defenders need before suspicious behavior can be investigated.

Browser Credential Theft Requires Endpoint Visibility

Because infostealers commonly target information stored around browsers and user sessions, endpoint security should monitor unusual access to browser-related files and sensitive application data.

Defenders should also consider enterprise browser policies, credential protection, application isolation and centralized identity controls.

The goal is not simply to detect malware after execution.

The goal is to make stolen data less useful even if malware reaches an endpoint.

MFA Is Important—but Not a Magic Shield

Multi-factor authentication remains one of the strongest defenses against stolen passwords, but organizations should not assume that MFA eliminates infostealer risk.

Attackers increasingly target authentication sessions, tokens and social-engineering workflows.

Phishing-resistant authentication, hardware-backed credentials and passkeys can reduce several forms of credential abuse more effectively than password-based MFA alone.

Identity Should Be Treated as an Attack Surface

The most important defensive shift is conceptual.

A user account is not merely an administrative object.

It is an attack surface.

Security teams should continuously ask:

Where can this identity authenticate?

What devices can use it?

What applications trust it?

What privileges does it possess?

Which sessions are currently active?

Can stolen credentials be rapidly revoked?

Can suspicious authentication be automatically blocked?

These questions turn identity from a passive directory entry into an actively monitored security boundary.

Vulnerability Prioritization Must Become Risk-Based

The growing number of vulnerability disclosures makes blanket patching increasingly difficult.

Organizations should prioritize vulnerabilities based on factors such as:

Internet exposure

Exploit availability

Active exploitation

Asset criticality

Privilege gained

Authentication requirements

Availability of compensating controls

Presence of sensitive data

Evidence of targeting

A vulnerability affecting an isolated test server should not necessarily receive the same immediate response as an actively exploited flaw affecting an Internet-facing identity system.

AI Raises the Speed of the Attack Lifecycle

The most concerning aspect of malicious AI is its ability to reduce friction.

Attackers can potentially generate more phishing variants, translate messages, analyze information and automate repetitive tasks faster than before.

Flashpoint’s broader 2026 reporting explicitly frames agentic AI as a force multiplier capable of automating portions of the attack lifecycle.

This means defenders need automation of their own.

Manual triage will increasingly struggle against machine-speed attacks.

The New Defensive Equation

The emerging equation is simple:

Attacker Automation

>

Human-Only Defense

Organizations need to move toward:

Continuous Visibility

+

Automated Detection

+

Risk-Based Prioritization

+

Rapid Identity Response

+

Threat Intelligence

That combination is much more realistic for a threat environment operating at machine speed.

What Undercode Say:

1. Infostealers Are Becoming an Identity Crisis

The biggest danger is not the malware itself.

It is what the malware steals.

  1. Passwords Are Only One Piece of the Puzzle

Modern infostealers can target authentication artifacts that may be more valuable than passwords.

3. The Criminal Economy Has Become Modular

Different criminals can specialize in infection, data processing, access brokering and extortion.

4. Automation Is Multiplying Criminal Capacity

Automation allows a relatively small operation to process enormous quantities of stolen information.

  1. Identity Is Moving to the Center of Cybersecurity

Organizations can no longer separate endpoint security from identity protection.

6. Session Theft Deserves More Attention

A stolen authenticated session can potentially bypass controls designed primarily around passwords.

7. Infostealers Can Become Initial Access Engines

The malware may ultimately serve as the first step toward corporate compromise.

8. The Endpoint Still Matters

Cloud security cannot compensate for completely compromised endpoints.

9. Vulnerability Numbers Are Becoming Overwhelming

Security teams are facing a volume problem as vulnerability disclosures continue to rise.

10. Not Every CVE Is Equally Dangerous

Threat intelligence is essential for separating theoretical exposure from practical risk.

11. Exploit Intelligence Is Critical

Knowing that exploit code exists can dramatically change the urgency of remediation.

12. The Patch Window Is Shrinking

Organizations increasingly need to respond within hours or days rather than weeks or months.

13. AI Is Becoming an Operational Tool

The conversation has moved beyond criminals merely experimenting with chatbots.

14. Agentic Systems Could Change Scale

Autonomous systems can potentially perform repetitive tasks continuously and rapidly.

15. Criminal Distribution Is Becoming Decentralized

Attackers can abuse legitimate platforms instead of maintaining every component themselves.

  1. Telegram Is Only Part of the Problem

The broader issue is the availability of communication, storage and development infrastructure.

17. Legitimate Services Can Become Criminal Infrastructure

The same platforms used by developers and businesses can sometimes be abused by attackers.

18. Ransomware Is Evolving

Encryption is increasingly only one component of extortion.

19. Data Theft Creates Additional Pressure

Sensitive information can remain valuable even when victims can recover encrypted files.

20. Identity Extortion Is Especially Dangerous

Attackers can threaten organizations with access, exposure and operational disruption simultaneously.

  1. Lower Payment Rates Do Not End Ransomware

Criminal groups can change tactics when victims refuse to pay.

  1. Cybercrime Is Becoming More Like a Business

Access, malware, infrastructure and data can all be bought and sold.

23. The Economics Favor Automation

Lower operational costs make attacks more scalable.

24. Defenders Need Their Own Automation

Security teams cannot manually investigate every alert or credential event.

25. Behavioral Detection Is Increasingly Important

Traditional signatures may not detect every new infostealer variant.

26. Authentication Telemetry Is Valuable

Unexpected login locations, devices and session patterns can reveal compromised accounts.

27. Endpoint Telemetry Must Feed Identity Defense

A compromised endpoint and suspicious account should be investigated as potentially related events.

28. Threat Intelligence Needs Context

Raw vulnerability counts are less useful than information about exploitation and exposure.

  1. Early Warning Can Create a Defensive Advantage

Knowing about emerging threats before mass exploitation can provide valuable preparation time.

30. Organizations Should Assume Credentials Will Leak

The defensive question should be what happens after credentials are stolen.

31. Zero Trust Becomes More Relevant

Every authentication event should be evaluated according to context and risk.

32. Privilege Reduction Matters

A stolen low-privilege account should not automatically become a path to an entire environment.

33. Rapid Revocation Is Essential

Organizations need the ability to invalidate compromised credentials and sessions quickly.

34. Passkeys Can Reduce Password Exposure

Moving away from reusable passwords can eliminate entire categories of credential theft.

35. Security Teams Need Cross-Domain Visibility

Endpoint, identity, cloud, vulnerability and threat intelligence teams cannot operate completely independently.

  1. The Attack Chain Is Now the Unit of Analysis

Investigating individual alerts can miss the relationship between seemingly unrelated events.

  1. AI Will Increase Both Offensive and Defensive Speed

The advantage will increasingly belong to whichever side can automate safely and effectively.

38. Human Judgment Still Matters

Automation can process signals, but analysts remain essential for understanding context and business impact.

39. The Biggest Risk Is Convergence

Infostealers, vulnerabilities, AI and ransomware become much more dangerous when combined.

40. The Security Industry Must Adapt

The era of defending one isolated threat at a time is fading. Organizations need continuous, intelligence-driven defense capable of responding to interconnected attacks.

✅ Flashpoint Is Reporting a Converging Threat Landscape

Flashpoint’s official 2026 Global Threat Intelligence Report confirms that identity, infostealers, vulnerabilities, ransomware and malicious AI are major themes in its research.

Its published material specifically describes a move toward agentic attack frameworks and identity-driven compromise.

⚠️ The 7.4 Million H1 2026 Figure Needs Context

The supplied article attributes the 7.4 million infected-device figure to a midyear Flashpoint dataset, but Flashpoint’s publicly accessible annual 2026 material prominently reports a different figure: more than 11.1 million infected machines during 2025.

Therefore, the 7.4 million number should be presented as a reported H1 2026 figure from the cited midyear edition, rather than being treated as a figure independently confirmed by Flashpoint’s publicly accessible annual summary.

❌ Some Numbers Should Not Be Presented as Independently Verified Facts

The specific claims of 1.7 billion credentials, 21,667 vulnerability disclosures, 239 actively exploited vulnerabilities, 6,808 pre-NVD findings, 22 million malicious-AI posts and 6,256 ransomware victims come from the supplied article’s account of the midyear report.

Flashpoint’s public 2026 materials currently emphasize different annual figures, including 3.3 billion compromised credentials and cloud tokens, a 12% increase in vulnerability disclosures and a 53% increase in ransomware incidents.

Prediction

(-1) Automated Credential Theft Will Continue Growing

The direction of travel is difficult to ignore. Infostealers are becoming cheaper to distribute, stolen credentials are increasingly valuable, and automation allows criminals to process compromised data at enormous scale.

As AI-driven systems become more capable, the distance between infection and account takeover is likely to become shorter.

(-1) Identity Attacks Will Become More Difficult to Detect

Attackers increasingly want to authenticate as legitimate users rather than behave like obviously malicious intruders.

That means future security incidents may involve fewer traditional malware indicators and more suspicious authentication behavior.

(-1) Ransomware Operators Will Continue Moving Toward Extortion

Even if encryption becomes less effective or fewer victims pay, attackers can adapt by stealing data, abusing identities and threatening disclosure.

The ransomware brand may eventually matter less than the underlying access-and-extortion business model.

(+1) Phishing-Resistant Authentication Will Become More Important

Passkeys and hardware-backed authentication can significantly reduce dependence on reusable passwords.

Organizations that combine these technologies with endpoint protection, session controls and rapid identity revocation should be better positioned against infostealer-driven compromise.

(+1) Security Automation Will Become a Defensive Necessity

The same automation that makes attacks faster can help defenders correlate endpoint, identity and vulnerability telemetry.

The organizations that successfully automate detection and response without sacrificing human oversight will have a major advantage.

The Bigger Warning for 2026

The most alarming message behind the numbers is not simply that millions of devices are being infected.

It is that stolen information is becoming increasingly usable at machine speed.

An infected laptop can produce credentials. Credentials can become access. Access can become data theft. Data theft can become extortion. AI can accelerate parts of the process. Vulnerabilities can provide additional pathways into organizations.

The boundaries between these threats are disappearing.

Flashpoint’s broader 2026 research describes precisely this convergence, warning that attackers are increasingly combining identity compromise, vulnerabilities, malware and autonomous systems into a high-velocity threat ecosystem.

For defenders, the lesson is straightforward: protecting the password is no longer enough.

The modern security strategy must protect the endpoint, the identity, the session, the application, the cloud environment and the vulnerability surface at the same time.

Because in the emerging cybercrime economy, the attacker does not need to defeat every security layer.

They only need to find the one that still trusts stolen access.

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube