Definition · Stealer log
What is a stealer log?
How a machine ends up in a stealer log, what the archive holds, where it circulates, why it weighs more than a database breach, and what to do when your domain appears in one. The word keeps coming up in alerts and incident reports without being explained. Here is how a machine ends up in a stealer log, what the archive holds, where it circulates, why it weighs more than a database breach, and what to do when your domain appears in one.
- Guide
- Definition
- Reading
- 6 min read
- Published
- Last updated
- Related services
- Infected devicesStolen sessionsCompromised credentialsExposed staff
In one sentence
A stealer log is the archive an information stealer produces on an infected machine: passwords saved in the browser, session cookies, forms, files and the system fingerprint, resold in batches on cybercriminal markets and exploitable until the accesses it holds have been revoked.
An information stealer runs once, copies what it finds and often vanishes without a trace. It arrives through a free utility, cracked software, a malicious advertisement or an attachment, and readily targets personal computers, where no corporate tool will see it.
The result is a log, the stealer log: one folder per machine, resold in batches or distributed in messaging channels, which buyers sort by domain, by service or by country. A work address in that log means a device that touched your services is infected.
What a log holds
The passwords saved in browsers, with the site address and the username; the session cookies, which replay a login with no password and no second factor as long as they are valid; the saved forms, addresses and cards included; files picked by keyword; sometimes screenshots and cryptocurrency wallets.
The system fingerprint completes it: machine name, operating system, hardware, IP address, infection date. It is what tells whether the device is a work computer or the household machine, and dates the infection.
Where it circulates and for how long
Fresh logs are first sold one by one or in small batches, then join free or almost free compilations, where they stay for months. The groups’ messaging channels and specialised marketplaces are their main trading places.
The delay that matters is the one between the infection and the first exploitation. It is measured in days, sometimes in hours for a session still open on a privileged service. That is why our collection partners acquire the logs as soon as they circulate, and why an alert must arrive the same day.
Why it is worse than a database breach
A leaked database delivers a password, often old and sometimes hashed. A log delivers a complete access: the cleartext password, the still-valid session that walks past multi-factor authentication, and the certainty that a device is infected and may still be sending what is typed on it.
The log also reaches what the company does not control: a personal computer used to read email, a contractor’s laptop, a household phone. Your internal detection will never see that machine; the only usable trace is the log itself.
What to do when your domain appears in one
In order: revoke the sessions open on the services concerned, reset the captured credentials, check in your logs that they have not already been used, then handle the device, reinstall included when it belongs to you, steps passed on to the person when it does not.
Finally, tell the person with a factual message, without blame: a log proves a machine is infected, not that an employee did wrong. The guide on responding to compromised credentials details every step, and the exposed-staff analysis places the person in the “device to protect” cohort until the action is recorded.
Frequently asked questions
Is an antivirus enough?
It stops some of them, not all: information stealers change their packaging faster than signatures do, and the infected device is often personal, outside any corporate tool. Monitoring the logs in circulation is the only way to know that a machine you do not manage has exposed your accesses.
Does multi-factor authentication protect against it?
Against the replay of a password, yes. Against the replay of an already authenticated session cookie, no: the session is opened after the second factor. The answer is revoking sessions, not only changing the password.
Can you tell which machine is infected?
The log carries the machine name, its operating system and its infection date; an analyst can usually tell a work computer from a personal device. We keep neither the passwords nor the cookies: the metadata is enough to decide what to revoke and whom to tell.
Are your domains already in a log?
A one-hour scoping call with an analyst says what the logs in circulation already hold on your perimeter, history included.
Bespoke offering: no public price, no packages.