New research How Rover caught a PAN-OS authentication bypass attempt (CVE-2025-0108) Baku · Dubai

Stealer Logs as a Subscription: How Sellers Run the Market Like a Business

Oct 7, 2026  /  Cypho Research Team  /  8 min read

Over the past month we handled persistent phishing against our customers, ongoing company impersonation, several leaks across platforms, and a steady flow of stealer logs that included accounts from organizations worldwide.

The stealer log market is not slowing down. In the listings we reviewed, sellers posted several new batches in a short time period, and some now run full storefronts with subscription pricing. This post looks at how these sellers operate as businesses and why that matters for defenders.

How we know

We reviewed public listing pages on underground forums, plus the public channels and websites sellers use to advertise. We looked at titles, dates, sizes, view counts and pricing. Listings are advertisements, so treat sizes, freshness and prices as claims.

The market in one view

Figure 1 is one page of a stealer-log board on a dark web forum, captured on 6 October 2026. The ten listings visible came from three sellers within about two days.

Figure 1. Ten listings on a stealer-log board, showing advertised ULP sizes, raw log archives, WordPress admin logins, dates and view counts.

Figure 1. One page of a stealer-log board, captured 6 October 2026 (the screenshot's "Today" is that date). Some identifiers are obscured; forum and seller branding remain visible.

  • Volume: Four listings give sizes, all ULP files (URL, login, password lines) of 755,000 to 1.2 million lines. Two others are raw log archives of 626 MB and 5.3 GB.
  • Freshness: Those two archives are labelled with 3 and 4 October dates.
  • Targets: Two listings advertise WordPress admin logins, which are a way into company websites.
  • Demand: The threads have no replies but up to 801 views each. Deals probably happen in private chats.

In October 2024 a global law enforcement operation disrupted infrastructure for the RedLine and META infostealers. The market did not stop. Other families filled the gap, and a forum post dated March 2025 was still advertising "RedLine logs" months after the action. Sellers sell supply rather than brands, so disrupting one brand does not stop the trade. Our supply-chain post explains why.

Where the logs come from

Stealer logs do not come from breached company systems. They come from infected user devices. Infostealer malware collects browser-saved passwords, cookies and autofill data, and the operators package it for sale. Common infection routes are pirated games and software, fake installers, malicious browser extensions and fake verification pages that trick people into running a command. One infected personal laptop used for work can expose corporate accounts. For more detail, see our posts on stealer logs and Chrome extensions.

What a stealer log contains

A single log is the harvest from one infected device. It usually holds browser-saved logins, autofill data, cookies and session tokens, saved payment details, crypto wallet files and basic system information such as the device name and location. Session cookies matter most to defenders, because a valid session can let an attacker into an account without the password and, in some cases, without triggering MFA. That is why a log that is a few days old is worth far more to a buyer than a list that has circulated for years.

From log to ULP line: how the product is packaged

Raw logs arrive as one archive of folders per victim, which is hard to search at scale. Sellers therefore parse them into flat URL:login:password (ULP) lines, remove duplicates and sort them by service, domain or country. Buyers then filter for what they want, such as VPN portals, admin panels, webmail or a specific company's domain. Labels like "private" and "UHQ" are marketing terms with no independent meaning, so a seller's claim of quality cannot be taken at face value.

A seller that runs like a SaaS company

Some sellers now offer subscriptions to a private "cloud" of logs instead of one-off files. Figure 2 shows one seller's public Telegram channel, which had about 3,000 subscribers at the time of capture.

The pricing post lists three plans: $200 for the first month, $100 for each renewal and $1,000 for lifetime access. The lifetime plan pays for itself in the ninth month ($200 plus eight renewals of $100), which is the usual trade-off between monthly and lifetime pricing at a SaaS company. The seller also claims "no duplicates", "no unknown" lines and "private" sourcing, and tells buyers to check the data themselves. A pinned message advertises validated accounts for several webmail providers. All of these are claims we cannot verify.

Subscriber counts are not customer counts, so we cannot estimate this seller's revenue. For illustration only: 50 paying subscribers on the $100 renewal plan would bring in $5,000 a month, which is enough to pay for hosting, new channels and support staff. At that scale the business needs very few customers to keep running, which helps explain why bans and takedowns slow sellers down without ending them.

Figure 2. A Telegram channel advertising $200 first-month, $100 renewal and $1,000 lifetime subscription plans, with contacts obscured.

Figure 2. A seller's Telegram channel advertising subscription pricing. Names and contacts are partially obscured.

The same marketing appears on the open web. Figure 3 is from a seller's own website, which presents the service as a "private network" with "5x/week" updates, "0 duplicates" and "24/7" access. These are availability and freshness promises of the kind legitimate SaaS vendors make.

Figure 3. A seller's website claiming five updates per week, zero duplicates and round-the-clock access to a private network.

Figure 3. A seller's website advertising update frequency and "clean" data. The logo is obscured, but the seller's name remains in the text.

Reputation is part of the product

Sellers build trust the way online marketplaces do. In Figure 4, a seller posted a 2.2-million-line ULP offer on 29 September 2026. The account holds a "Verified Seller" badge and a reaction score of 3,497. It joined in November 2025 and has 785 messages, so roughly ten months of activity. The download link is hidden until the reader reacts to the post, a mechanic that boosts the post's visibility.

Figure 4. A 2.2-million-line ULP offer with a Verified Seller badge, account activity statistics and a download hidden behind a reaction.

Figure 4. A vendor post with trust badges and content hidden behind a reaction. Some identifiers are obscured.

Free material works as advertising too. Sellers post free logs on forums with links to their Telegram channels, and when Telegram bans a channel they publish a new one.

Why Telegram is the storefront

Telegram gives sellers a free storefront, a payment conversation and a delivery channel in one app. In Figure 2 the seller lists separate contacts for support, a "gateway" and a bot, which suggests a division of roles between sales, access and automation. Channels are cheap to recreate, and a new channel can be announced from the old one, from forum posts and from a website. This is why banning a channel rarely removes a seller for long, and why tracking the seller's behavior and content is more durable than tracking a single channel.

What we saw in the data

ULP files and combo lists are the main product in these listings. Based on how sellers describe them, they mostly contain the following.

  • Everyday consumer logins: Email, social media, streaming, gaming and shopping accounts make up most of the lines, because that is what ordinary users save in their browsers.
  • Work access mixed in: Corporate and government accounts appear when people use an infected personal device for work. These include VPN portals, webmail, single sign-on pages and admin panels such as WordPress.
  • Victim company URL plus login: Global mix ULP files contain the URL of the victim company and a user and password. Some sellers advertise lists focused on certain regions, so the targets vary depending on the supplier.
  • Combo lists: Combos are usually shorter email or username and password pairs without the URL, so they say less about where the account is used.

Why this matters

Sellers specialise, compete on freshness and sell to anyone who pays. The practical conclusion for defenders is to assume that credentials from an infected device reach the market within days, and to shorten the time between exposure and response.

Where defenders can counter it

What we saw Where to counter it
Logs offered within days of capture Invalidate sessions quickly and shorten session lifetimes
Raw WordPress and other admin login lines Put MFA and IP restrictions on admin panels
Subscription access to bulk data Monitor your domains and staff in exposure data and rotate credentials on a match
Government and corporate accounts mixed with personal-device logs Keep work and personal browsers apart and disable browser password saving on managed devices
Brands and channels rebuilt after bans or takedowns Track exposure and behavior, not family names

If you find your accounts in a log: the first 24 hours

  • Start with the device. Identify which machine was infected and clean it before resetting anything. A password changed from an infected device can be stolen again.
  • Revoke sessions and tokens for the affected accounts, not just the password, and sign out all active devices.
  • Check for persistence: new MFA devices, mail forwarding rules, OAuth app grants and recent logins from unfamiliar locations.
  • Rotate related credentials, including reused passwords and any secrets saved in the same browser.
  • Record what you found and when, so the exposure can be reviewed later and affected parties can be told where required.

Common questions

What is a ULP file?

A list of lines in URL:login:password format, usually extracted from stealer logs. Buyers filter it for the targets they want.

Is a stealer log the same as a data breach?

No. A breach is a compromise of a company's systems. A stealer log comes from a single infected device, and one person's log can expose many accounts.

Why do sellers survive takedowns?

The work is split across specialists, and brands are easy to replace. Our supply-chain post covers this in more detail.

To check whether your domain appears in exposure data, try the free exposure search in Cypho Signals, which shows counts, indexing dates and a masked preview, not raw credentials. To see how Cypho monitors the sources where logs are traded, contact our team.

Unknown threats are unstoppable. Until we expose them.

Send us your company domain. We'll walk you through what's already out there about you and how Cypho would handle it, with one of our analysts on the call.

Or write to [email protected]

We'll use your details to respond to your request. See our privacy policy.