The Stealer Log Supply Chain: Who Does What

When people picture a stealer log, they often picture one criminal doing everything: writing malware, infecting a computer, and draining an account. The public listings on underground forums show something closer to an assembly line. Each step is sold as a separate service, and different people do each one.
That matters for defenders, because every step is a place to interrupt the chain. This post walks through the roles we could see in public forum listings and where each one can be countered.
How we know
We read public thread titles, dates, replies and views on the malware and log boards of several underground forums, without logging in. We did not open threads, buy anything or download files. Titles are advertisements, so treat prices and success rates as claims. We are not naming forums or sellers.
Stage 1: Stealer developers
The chain starts with people who build and rent infostealers. Listings name many families, including Vidar, LummaC2, StealC, RedLine, DanaBot, Banshee for macOS and newer names we won't list here. They are sold as a subscription or a rental, often with support.
Sales pitches quote a "knockback" rate, commonly 80 to 90 percent, which appears to mean the share of infections that report back to the buyer. They also advertise how quickly they adapt to browser defenses, with titles mentioning bypasses for Chrome's newer encryption and support for recent browser versions.
Where to counter it: keep browsers and endpoint tools current, and prefer hardware-backed authentication so that a stolen password or cookie is worth less.
Stage 2: Install and traffic sellers
A stealer needs victims. A separate group sells "installs" by country and operating system, advertised as running around the clock, "unique only", with discounts on bulk. Others sell loaders, botnet services and scripts that trick people into running a command themselves, such as fake-verification pages.
The person buying installs may never write or touch the malware. They pay for infected machines and deliver their own payload.
Where to counter it: train people on fake software downloads and fake verification prompts, and restrict where employees can run installers from.
Stage 3: Evasion services
Between the malware and the victim sit services that make detection harder. Listings offer crypters that repackage a file so scanners miss it, scanning services that check a file against dozens of antivirus engines, code-signing certificates advertised at roughly $1,500 to $3,500, and tools aimed at switching off endpoint security products.
Where to counter it: do not rely on signature scanning alone. Behavior-based detection catches what a repackaged file hides, and application control limits what can run at all.
Stage 4: Log owners and processors
Once the malware reports back, the log owner has a stack of stolen data. Many do not cash it out themselves. Instead they hand it to a processor who works the logs and shares the profit. The splits quoted in listings include 50/50 for retail accounts, 60/40 for automated processing, 70/30 for general use and 80/20 for crypto-casino accounts.
Some listings mention hidden remote-control tools used to operate from the victim's own device or browser profile, which helps them avoid the "new device" checks that would catch a login from somewhere strange.

Public listing titles offering to process logs and search log databases. Usernames and shop names are blurred, and the forum's name is removed.
Batches are often labeled by the stealer that produced them, the country and the operating system, with a count, for example "2,500 logs, Canada, Windows 10". That labeling lets buyers pick the geography and device type they want.
Where to counter it: invalidate sessions quickly, and watch for logins that reuse a valid session from an unfamiliar context.
Stage 5: Search clouds and cash-out
The final layer turns stolen data into money. Some sellers offer to "extract your target" from databases of billions of URL, login and password lines, with subscriptions and chat-bot interfaces. Others run services that remove two-factor protection from exchange accounts, or that turn bank and brokerage access into withdrawals. Claims of large sums appear in titles, but we cannot verify any of them.
Pricing can be per query. One listing offered to pull a buyer's request from a 1.5 TB collection for a fixed $30, and some run chat-bots that take a domain and return matches. At the far end, account shops appear to sell single business logins for roughly $19 to $56 each, though the listings do not say where the accounts came from.
Where to counter it: monitor exposure data for your domains and staff, so you learn about a match before a buyer acts on it.
The chain at a glance
| Stage | What is sold | Where defenders can interrupt |
|---|---|---|
| Stealer developers | Malware rentals and builds | Patching, hardware-backed MFA |
| Install and traffic sellers | Infected machines, loaders, lures | User training, application control |
| Evasion services | Crypters, scanners, signing certificates | Behavior-based detection |
| Log owners and processors | Log handling for a share of profit | Fast session invalidation |
| Search clouds and cash-out | Queries by domain, account takeover | Exposure monitoring, credential rotation |
Why the chain view helps
Thinking of it as one attacker makes the problem feel unbeatable. Thinking of it as five specialists makes it clear that you do not need to stop every stage. Break one, and the next stage has nothing to work with. Endpoint controls stop infections. Good identity controls limit what a stolen session can do. Exposure monitoring tells you when a log reaches the market.
For the buyer's side of the story, read what buyers want in a stealer log. For what happens after a log is sold, read what happens to stealer logs after the sale. For detection, see our stealer log detection guide.
Common questions
Who uses stealer logs? Different people at different stages: malware developers, install sellers, log owners, processors who cash accounts out, and buyers who search for a specific target.
Are stealer developers the same people who use the logs? Often not. Listings show developers renting malware to others, and log owners passing logs to processors for a share of the proceeds.
Where can defenders break the chain? At any stage: prevent infection, limit what a stolen session can do, and monitor exposure so you can rotate credentials before a buyer uses them.
To see whether your domain appears in exposure data, try the free exposure search in Cypho Signals, which shows counts, indexing dates and a masked preview, not raw credentials. To see how Cypho monitors the sources where logs are traded, contact our team.