Definition
What is stealer log monitoring?
Stealer log monitoring is the continuous search of files exfiltrated by infostealer malware — saved passwords, session cookies, and autofill data taken from infected computers — for records tied to your domain, so credentials can be reset and sessions revoked before an attacker uses them to log in.
What an infostealer actually takes
An infostealer is malware with a narrow job: get onto a machine, empty it of anything that can be used to authenticate, and leave. It is usually delivered through cracked software, malicious ads, fake installers, or a lure in a browser download — not through a sophisticated intrusion.
Once it runs, it collects, in a single pass:
- Browser credentials the malware can access, often recovered in plaintext.
- Session cookies and authentication tokens for services the user is currently signed in to.
- Autofill data — addresses, payment details, anything the browser has been asked to remember.
- System metadata: hostname, operating system, installed antivirus, IP address, and often a screenshot.
The result is packaged as a stealer log: a folder of text files, one infected machine per log, sold or traded in bulk on dark-web markets and in Telegram channels.
Why a breach-notification check misses them
Breach-notification services answer a different question. They index databases that companies have lost, so they tell you which services leaked an account you hold. Depending on the incident, that data may be older and may contain password hashes rather than a directly usable credential.
A stealer log inverts the relationship. Nothing at your company was breached — an employee's device was. What leaks is not one account at one service but every account saved in that browser, in plaintext, alongside the live cookies that make a password optional. A corporate VPN credential, an admin panel, and an internal wiki login can all appear in the same file, days rather than years after the infection.
This is why an organization can pass every breach check it runs and still have valid, working credentials for sale.
The scale, in measured numbers
Alphatechs, the team behind SphereTI, tracked infostealer activity across a 60-day window from 20 March to 20 May 2025, spanning the international operation that disrupted Lumma Stealer:
- 881,387 compromised systems observed across the 60-day period
- 242,091 infections attributed to Lumma Stealer alone — 27.5% of the total
- 26,758 systems infected on the single busiest day, 11 May 2025
- 786,041 antivirus installations present on machines that were compromised anyway
Source: Lumma Stealer Disruption: A Comprehensive Analysis of the World's Most Prolific Infostealer Takedown, Brenton, CTO, Alphatechs, 9 September 2025.
The last figure is the one worth sitting with. The source recorded 786,041 antivirus installations across compromised systems. Having endpoint protection installed did not prevent every infection in the observed dataset; prevention is not a substitute for knowing what has already left.
What monitoring involves
Monitoring is the standing version of a one-off check. In practice it means four things:
- Collection. Continuously pulling new logs from the markets, forums, and channels where they are traded, as they are posted rather than when they are eventually aggregated.
- Matching. Searching each new log for identifiers tied to your organization — your domain in an email address, but also your domain in a saved URL, which is how you find the contractor whose personal machine holds a login to your systems.
- Context. Establishing what was actually exposed: which credential, for which system, from which machine, and when.
- Alerting. Telling someone in time to act, with the detail needed to act.
What to do when you appear in one
Speed matters more than thoroughness in the first hour, because the credential is already in circulation. In order:
- Reset the exposed credential and any credential reused alongside it.
- Invalidate active sessions for the affected accounts — this is the step most often skipped, and the one that closes the cookie.
- Treat the device as compromised, not just the account. The log tells you which machine it came from.
- Check what else was in the same log. One infection rarely exposes one account.
How SphereTI approaches it
Dark web and stealer log monitoring is one of five modules in the platform. SphereTI continuously scans dark-web markets and stealer-log dumps for credentials and data linked to your domain, and alerts you when something appears — with an explanation of what was found, why it matters, and what to do next. The product tour shows the credential search itself: the domain, email-domain and IP filters, and where the results land.
The free exposure report is the same check, narrowed to a single address: enter a work email and it is compared against known breaches and stealer logs. It never asks for a password.
Check your own exposure
Enter a work email and SphereTI checks it against known breaches and stealer logs, then shows you which credentials have been exposed. Free, and it never asks for your password.
Get your free report