Free vs. Premium: The Hidden Pricing Model Behind Stolen Credentials

Free vs. Premium: The Hidden Pricing Model Behind Stolen Credentials

It usually starts with something small. An employee downloads a cracked design tool on their personal laptop, or clicks a fake software update while gaming after work. Within seconds, an infostealer runs quietly in the background, pulls everything saved in the browser, and disappears. No ransom note, no alert, no obvious sign anything happened.

That "everything" is the problem. A single infected device can hand an attacker far more than one password. Recent research profiling infostealer victims found individual logs containing over 1,300 distinct pieces of personal and organizational data, often blending personal and corporate accounts on the same machine.

This is no longer a fringe threat. For the first time in Mandiant's tracking history, stolen credentials overtook email phishing as an initial infection vector in 2024, rising from 10% to 16% of investigated intrusions, driven almost entirely by infostealer malware.

And that data doesn't move through one uniform market. Some is handed out for free, used as bait to build an audience. Some is sold for hundreds of dollars a month to buyers who know exactly what they're looking for. Understanding why that split exists, and what separates a worthless free sample from a corporate credential worth real money, is what this post breaks down, along with what a single credential can expose inside an organization, and how a real breach, the 2024 Snowflake customer compromises, shows exactly how far that chain can run.


What Are Stealer Logs?

What Are Stealer Logs?

An infostealer is a simple piece of software with one job: quietly copy anything of value stored on a device and send it back to whoever is running it. That includes usernames and passwords, active session cookies, autofill data, credentials for FTP and VPN clients, messenger data, crypto wallet files, and system fingerprint information.

Once collected, this data gets bundled into a single package per infected device, known as a "log." One log corresponds to one infected machine, but that machine can easily belong to someone logged into a dozen personal accounts and several corporate ones from the same browser.

Many modern stealer families are built with direct Telegram integration: once harvesting finishes, the malware packages everything and sends it straight to an operator-controlled Telegram chat through the platform's own Bot API. No separate infrastructure needed. Families like Redline, Vidar, Raccoon, and Lumma are sold as Malware-as-a-Service, so anyone willing to pay a subscription can run their own infection campaign, producing a steady, high-volume stream of logs.

What happens to a log next, dumped for free or sold for a few hundred dollars a month, depends entirely on what's inside it.

How a stealer log is created


Anatomy of a Stealer Log

Anatomy of a Stealer Log

Sellers typically convert harvested credentials into a standardized format called ULP, short for URL:Login:Password. One line per credential, URL, username, and password separated by colons. This is what makes stealer logs so tradeable in bulk: a single archive can hold thousands of ULP lines from dozens of services on one machine.

Below is an illustrative example, built with placeholder domains and fake credentials, not real data:

netflix.com:user_demo01:••••••••••
paypal.com:[email protected]:••••••••••
company-vpn.example.com:j.doe:••••••••••
crm.example-corp.com:admin_temp:••••••••••
outlook.office.com:[email protected]:••••••••••
aws.amazon.com:iam-test-user:••••••••••
okta.example-corp.com:s.miller:••••••••••
salesforce.com:[email protected]:••••••••••
docusign.net:[email protected]:••••••••••
chase.com:demo_banking_user:••••••••••
github.com:dev-test-account:••••••••••
binance.com:demo_trader99:••••••••••

Real logs sold on Telegram and dark web marketplaces look almost exactly like this, just with real domains, usernames, and passwords. Redline and Vidar are two of the families most consistently associated with large-scale ULP data. The format is also why a log can be priced so quickly: a buyer can just search for a specific domain, like a company's VPN portal, and immediately know if that organization is represented.

A ULP list full of expired streaming logins is nearly worthless. A ULP list with even one line pointing to a corporate SSO or VPN domain is a different category of asset entirely, which is exactly what the next section breaks down.


Free vs. Premium Stealer Logs

Free vs. Premium Stealer Logs

The difference in pricing isn't random. It maps almost directly onto what's inside the ULP list. Flare's research team, after analyzing more than 19.6 million stealer logs, settled on a three-tier way of classifying value:

  • Tier 1, corporate IT / business applications. SSO logins, VPN portals, cloud consoles, CRM systems.
  • Tier 2, infected devices with banking access. Online banking, payment platforms, financial services.
  • Tier 3, consumer applications. Streaming, gaming, social media, e-commerce, the bulk of a typical infection.

Most free-tier data falls into Tier 3. Sellers aren't being generous, a log full of Netflix and Steam logins isn't worth much anyway, so giving it away costs nothing and does real marketing work: free channels attract followers and demonstrate that a seller's operation is active. Tier 1 and Tier 2 data rarely shows up for free. It's gated behind invite-only or paid Telegram rooms, typically $200 to $1,000 a month depending on freshness and exclusivity, priced as functioning almost like legitimate subscription services.

Free tier Premium tier
Typical content Consumer apps, streaming, gaming Corporate SSO, VPN, banking, cloud
Freshness Often stale or recycled Fresh, updated regularly
Access Public channels Invite-only / paid rooms
Price $0 Roughly $200–$1,000/month
Typical buyer Casual actors, low-effort fraud Initial access brokers, targeted attackers

Who buys each tier. Free-tier buyers are rarely targeted. Many run credential-stuffing tools against dozens of sites, betting on password reuse, or are newer players without the budget for paid rooms. Premium buyers know what they're looking for, chief among them initial access brokers, who buy corporate access and resell it to ransomware affiliates. Research into underground marketplaces shows these buyers actively hunting for named access types, CRM, RDP, VPN, rather than browsing whatever shows up. That's the buyer type behind the Snowflake case discussed later.

Why Telegram dominates. Dark web markets like Russian Market still move volume, but they come with friction: Tor, onboarding, reputation requirements. Telegram has none of that, which is exactly what makes the free-tier model work as marketing. A single channel will often advertise both tiers side by side: a free public section next to a paid "VIP" room pitch. The free section is the storefront window; the private room is the shop behind it.

None of this means free logs are worthless, a point worth its own section later. But the split is a reasonably accurate signal of what's inside the archive before anyone opens it.


What Makes a Stealer Log Valuable?

What Makes a Stealer Log Valuable?

Beyond tier and freshness, buyers weigh a few specific factors:

  • Completeness. A full browser profile with payment data and autofill history gives more angles than a handful of saved logins.
  • Credential type. A corporate SSO or active VPN session is worth far more than a reused streaming password, since it can unlock an entire environment, not just one account.
  • Corporate context. A log tied to an identifiable company (corporate email domain, internal system URL) is worth more than an anonymous consumer log.
  • Session information. A live session cookie can let an attacker log in directly, bypassing password and MFA. Even an expired cookie leaves autofill data useful for social engineering a help desk.

What Can a Stealer Compromise?

What Can a Stealer Compromise?

The examples so far have mostly focused on individual credentials, one login, one service. But that framing understates what a real stealer log contains, because the harvesting process doesn't discriminate. It grabs everything the browser has stored, all at once, from every profile on the device.

Identity & SSO. Single sign-on centralizes authentication behind one identity provider, which is convenient for users and, once compromised, extremely efficient for an attacker: breaching one identity means inheriting everything it was allowed to touch. Often the password isn't even the weak point. Stealer logs frequently include the live session cookie alongside the credential, letting an attacker load an already-authenticated session and skip the login screen (and any MFA challenge) entirely. Even an expired cookie usually leaves behind autofill data, names, addresses, security answers, that's often enough to social-engineer a help desk into resetting MFA.

Cloud & DevOps. A developer's browser profile doesn't just hold personal logins. It holds cloud console access, API keys, and deployment credentials saved the same way anyone saves a Netflix password. Newer stealer variants are built specifically to hunt for cloud tokens and developer secrets, because a single stolen cloud credential can expose an entire production environment or deployment pipeline, not just one webpage.

VPN & RDP. Most stolen credentials open a door to a single room. A working VPN or RDP credential opens the building itself. Once authenticated, the attacker is no longer probing from outside, they're on the internal network exactly as an employee would be, with every perimeter defense the organization built now irrelevant.

Email & communication. Corporate email often sits in the same browser as everything else. A compromised email account hands an attacker both a system and the victim's voice, letting them reply to real threads or approve real invoices without raising suspicion.

Financial & crypto. Banking credentials convert to money with little effort in between, which is exactly why they command a premium. Crypto wallet theft is often instant and irreversible, with no chargeback available once funds move.

Internal & customer data. Wikis, ticketing systems, and shared drives that surface simply because they were logged in on the same infected machine. It's rarely one dramatic login that causes a breach. It's the accumulated overlap of dozens of ordinary ones, sitting quietly in a single log.

That overlap is exactly the pattern the next section traces through a real, documented incident.


From a Single Credential to an Organizational Risk

From a Single Credential to an Organizational Risk

The 2024 Snowflake customer breaches are a well-documented example of where this chain leads. Starting in April 2024, a threat actor tracked as UNC5537 systematically compromised Snowflake customer instances, eventually impacting roughly 165 companies. Stolen data was used for direct extortion. Mandiant found no evidence Snowflake's own platform had been breached; the root cause, every time, was compromised customer credentials.

At least 79.7% of the accounts UNC5537 used had prior credential exposure from earlier infostealer infections, involving familiar names: Vidar, Redline, Raccoon Stealer, Lumma, Risepro, Metastealer. Some credentials dated back to infections as early as November 2020, nearly four years old, and were still valid because the passwords had never been rotated.

That detail matters. This wasn't an attacker moving fast on a fresh premium log. Old, previously exposed credentials, exactly the kind that circulate for free or get recycled through forums, were still functional years later. None of the compromised accounts had MFA enabled or network allow lists, and several initial infections happened on contractor devices also used for gaming and pirated software downloads, still among the most common infection vectors today.

The Snowflake case is a clean demonstration of the mechanism this post describes: a stealer log isn't a one-time snapshot of risk. A single credential, exposed once, can remain exploitable for years, moving between free dumps, resale channels, and buyer inventories, until someone with the patience to search finally puts it to use.


Why Free Logs Still Matter

Why Free Logs Still Matter

Free logs are mostly framed as bait: stale, recycled, low-value. That's mostly accurate, but treating them as safe to ignore is its own mistake.

"Already exposed" and "no longer dangerous" aren't the same thing. The Snowflake breach proves it directly, credentials from 2020 were still valid in 2024 simply because nobody rotated them. There's also password reuse: a free log full of expired logins can still hand an attacker a working password the same person is likely using elsewhere.

Free channels also matter for defenders specifically, since they're the easiest part of this ecosystem to actually observe. Anyone can join a public Telegram channel and search it, making these channels one of the few useful vantage points for spotting exposure early, before the same data quietly migrates into a gated room nobody outside the buyer circle will ever see. That's a different, and arguably more useful, signal than "will this specific credential get exploited."


Turning Stealer Logs into Threat Intelligence

Turning Stealer Logs into Threat Intelligence

Massive volumes of logs, split across free and paid tiers, scattered across public channels and gated rooms, aren't intelligence on their own. Finding a company's domain inside a log dump is the easy part. The hard part is everything after: is this credential still valid, who does it belong to, what does it actually unlock, has it been circulating for months or does it just now appear? Without answering those questions, a raw hit is just an alert with no context, indistinguishable from thousands of others.

This is the same structural problem covered in our earlier post on moving beyond simple IOC feeds: a raw indicator tells you almost nothing on its own. Closing that gap means enriching raw hits against known organizational domains and employee identities, then prioritizing them, since a credential paired with a live SSO session cookie is a very different finding than an expired login to a personal streaming account that happens to share a company's name. A credential from a free public Telegram dump and one from a $500-a-month private VIP room can look identical in raw form, same ULP structure, same fields, but they carry very different implications about freshness and urgency. Context is what tells those two apart, and it's what tells a security team which of the thousands of exposed credentials circulating right now actually deserves attention today.


How Organizations Can Respond

How Organizations Can Respond

Everything covered so far describes the problem from the outside, how data moves, what it's worth, what it can unlock. Given all of that, here's what an organization can actually do about it.

Detect exposure early. Nobody knows their personal laptop is infected until something goes wrong, and by then the log has likely already been packaged and sold. Monitoring across both free and premium stealer log sources matters precisely because free channels serve as an early visibility window, catching a company domain or employee credential the moment it surfaces rather than months later.

Rotate credentials proactively, not just reactively. The Snowflake case makes this better than any general advice could: credentials from 2020 infections were still valid and exploitable in 2024, purely because nobody had ever rotated them. That's not a sophisticated attack defeating a sophisticated defense, it's a basic hygiene gap that persisted for years.

Revoke sessions, not just passwords. Stealer logs frequently include live session cookies alongside credentials, and a cookie doesn't care whether the password behind it changed. An attacker holding a valid session can often stay authenticated straight through a password reset unless that session is explicitly revoked.

Enforce MFA. None of the Snowflake accounts UNC5537 accessed had multi-factor authentication enabled. MFA doesn't stop a credential from being stolen, but it substantially raises the bar for a stolen credential to actually be usable, particularly against the "just log in with the harvested password" scenario free and low-tier logs enable most easily.

Restrict what employees can install. Infostealer infections overwhelmingly start with an employee downloading something they shouldn't on a device that also has work credentials saved, exactly what happened on the contractor systems in the Snowflake case. Restricting unauthorized software on devices that touch corporate systems closes off the most common infection vector before it ever produces a log.

Investigate the endpoint, not just the credential. If a log surfaced, it came from an actual infected device, likely with more than one credential exposed. Investigating the endpoint itself, rather than just remediating the one finding that triggered the alert, catches everything else sitting in that same log before it becomes a second incident.

None of these steps work well in isolation. Detection without rotation just produces a list of known problems left unaddressed. Rotation without session revocation leaves a live door open behind a changed lock.


Conclusion — The Value Is in the Context

Conclusion — The Value Is in the Context

A stolen credential, by itself, doesn't tell you very much. It's a username, a password, maybe a cookie, a fragment with no inherent meaning until it's placed next to the right questions: What does it open? Who does it belong to? How long has it been exposed? What does its presence reveal about the organization behind it?

Those questions separate a worthless free sample from a corporate credential worth hundreds of dollars a month. They separate a stale, years-old login from the exact same credential still working against a company that never rotated it. In raw form, the data is nearly identical either way, a line of text in a ULP file. Context is what tells the two apart, and it's also what tells a security team which of the thousands of exposed credentials circulating right now actually deserves attention today.

The free-versus-premium split isn't a pricing quirk. It's a rough, market-driven signal of what's inside a log before anyone opens it. The Snowflake breach wasn't a failure of sophisticated defenses; it was ordinary, years-old exposure nobody had contextualized in time. A stolen credential is only ever the starting point. What it becomes, a dead end or a breach, depends entirely on whether anyone was paying attention to the context around it.


Related reading from Cypho:


References:

Experience Next Generation Threat Intelligence

Minimize complexity and maintain secure posture with real-time monitoring and actionable insights

Get a Demo