New research How Rover caught a PAN-OS authentication bypass attempt (CVE-2025-0108) Baku · Dubai

What Do Buyers Want in a Stealer Log?

Sep 29, 2026  /  Cypho Research Team  /  6 min read

A stealer log is the package of data an infostealer collects from one infected device: saved browser passwords, session cookies, autofill data, crypto-wallet files and a fingerprint of the machine. Criminals sell these logs, and buyers rarely shop for "credentials" in general. They shop for access to specific services.

We read the public listings on several underground marketplaces to see what buyers ask for. This post covers what stood out, why it matters, and what defenders can monitor so that a stolen log is worth less to the person holding it.

What we looked at

We read public thread titles, dates, reply counts and view counts on the log-related boards of several underground forums, without logging in. That covers a few hundred threads posted between 2024 and 2026. We did not open threads, buy anything, download files or contact sellers.

Read the findings with that in mind. A title is a claim, not proof. These forums contain scams and recycled ads, and we cannot verify that any seller has what they advertise. What the boards do show reliably is what buyers ask for, because a buy request tells you about demand whether or not anyone fills it.

We are not naming the forums or any seller, and we are not linking to them.

1. Bank and payment access is the main product

Bank logs are the largest single theme. Roughly 20 of the 48 threads on one board's middle pages were about them: shops open "24/7", buy requests, cash-out services and marketplaces. The term appears to mean logs that include online-banking access.

Payment processors, merchant accounts, payment apps, brokerage accounts and crypto wallets show up in the same threads. Some are basic how-to guides on turning bank access into money, which tells you the audience includes newcomers.

For defenders: consumer and business banking sessions on employee devices are part of your exposure, even when the device is personal.

2. Buyers shop by service and domain

Many threads name the exact service the buyer wants: retail sites, marketplaces, ad platforms, payment processors, betting sites, freight and ticketing accounts. Several say "buying my request in your logs" or "check your links in my logs". As we read them, a buyer names a target and pays for matches from the seller's stock.

This is how searchable log databases work. You query by domain and get every log that contains a login for it, so your company's domains, and the third-party services your employees use, are the search terms.

Public thread titles on an underground logs board. Buyers ask for full email access, bank logs, ticket-site logs and logs for payment and lending apps. Usernames, dates and shop names are blurred.

Public thread titles on an underground logs board, showing what buyers ask for. Usernames, dates and shop names are blurred, and the forum's name is removed.

For defenders: monitor your own domains and the SaaS and fintech services your staff rely on, not only your VPN and single sign-on.

3. Email access and session cookies multiply the value

"Full email access" appears as a selling point in several buy requests. Two separate requests ask for Gmail cookies alongside email and password lists.

The reason is easy to see. Mailbox access lets an attacker use "forgot password" on other accounts. A live session cookie can let them skip the login and the MFA prompt entirely. A log with both is worth far more than a list of passwords.

For defenders: treat a mailbox in a log as a wider compromise than that one account, and treat cookies as credentials.

4. Freshness earns a premium, but old logs still get used

Sellers advertise "fresh", "live video proofs" and "online access + pin". Buyers ask for logs "only fresh from first hands" and for particular countries, including Canada, Germany, Finland, Israel and Spain.

But freshness is not the whole story. One service that brute-forces social-media accounts says it accepts logs "even from 2020". Old sessions expire, yet old passwords are often reused, so an old log can still open doors.

For defenders: speed reduces the value of a log, but do not assume an old exposure is harmless. Rotate the credentials whatever the log's age.

5. The barrier to entry is low

The boards include "for beginners" guides, a tutorial on connecting to bank data and a live course sold through Telegram. Many buy requests get one reply or none but still draw two to three thousand views, so more people are looking for logs than there are visible sellers.

The scale is visible too. At least one underground forum has a board devoted to stealer logs, with well over a hundred pages of listings, and drops on it can be labeled with the same day's date.

Cypho indexes log collections and leak-data files like these, and anyone can check their own organization against them. The free exposure search in Cypho Signals takes a domain or an email address, with no sign-in.

The Cypho Signals exposure search, with a domain field and a note that only the first character of usernames and passwords is shown

You get counts, indexing dates and a masked preview, where only the first character of each username and password is shown. Raw credentials are never displayed. Two limits to keep in mind: an indexing date is when Cypho indexed a file, not when the infection or breach happened, and an empty result does not prove a domain is safe.

Search your domain in Cypho Signals

What to monitor

What buyers look for What to watch
Logs for a specific domain Your company domains and key third-party services in exposure data
Bank and payment access Financial and payroll accounts used from employee devices
Full email access Corporate mailboxes appearing with stored credentials or cookies
Session cookies Sessions used from a new device or location; long session lifetimes
Fresh and old logs alike How quickly you can find a match, and rotating credentials whatever the age

If you find a match

  1. Reimage the infected device.
  2. Invalidate all active sessions, including cookies.
  3. Rotate every credential the device stored.
  4. Review authentication logs for access you don't recognize.
  5. Assume any sensitive data on the device was exposed.

For a fuller playbook, see our post on stealer log detection. For the basics, read what stealer logs are. To see where logs come from, read the stealer log supply chain, and to see what happens after a sale, read what happens to stealer logs after the sale.

Common questions

What is a stealer log? A file package an infostealer collects from one infected device, including saved passwords, session cookies, autofill data, wallet files and system details.

What do buyers want in stealer logs? Based on the public listings we read: bank and payment access, logs for specific services or domains, full email access, live session cookies, and logs from particular countries.

Do old stealer logs still matter? Yes. Fresh logs sell at a premium, but older ones are still worked, so rotate credentials regardless of a log's age.

How do I know if my organization appears in a stealer log? Monitor your domains and employee accounts in exposure data. You can start with the free exposure search in Cypho Signals, which shows counts, indexing dates and a masked preview, not raw credentials. Cypho's platform monitors the sources where logs are traded and alerts you when your domains appear. To see it in action, contact our team.


Related reading from Cypho: - Data Leak and Dark Web Monitoring — monitor underground markets for your organization's compromised credentials and data - Threat Intelligence Platform — explore how Cypho uses intelligence-driven automation to accelerate detection and response

Unknown threats are unstoppable. Until we expose them.

Send us your company domain. We'll walk you through what's already out there about you and how Cypho would handle it, with one of our analysts on the call.

Or write to [email protected]

We'll use your details to respond to your request. See our privacy policy.