Infostealers: the breach behind most breaches, and the one your business probably already has

By Ubuntu Guard | 9 June 2026

The Nullsec dumps that named SARS and SITA two weeks ago looked like a fresh government hack. Independent threat researchers reading the file shape said the data was almost certainly stitched together from infostealer logs harvested off thousands of personal laptops over the preceding months.

The phrase "infostealer logs" is the most under-explained term in South African cybersecurity coverage. Once you understand it, the entire credential-leak news cycle becomes legible. You stop reacting to each headline and start seeing the market that produces them.

Most South African SME breaches do not start with a sophisticated attack on your systems. They start with a piece of malware on someone's personal computer — often a family member's laptop — that quietly harvests every password the user types. The credentials then get sold by the bundle to whoever pays a few dollars on a forum. Six months later, someone tries those credentials against your Office 365 tenant and they work.

What an infostealer is

An infostealer is a small piece of malware whose only job is to take credentials and other secrets off a computer and ship them to a remote operator. The dominant families running in 2025 and 2026 are Redline, Lumma, StealC, Vidar, Atomic Stealer (macOS), and a rotating cast of newer entrants. They are sold as malware-as-a-service on Telegram and dark-web forums, with prices starting at around $200 a month. Anyone with a card and a grievance can run one.

Once installed, an infostealer takes about 30 seconds to do its work. It grabs every saved password from every browser on the machine. It grabs cookies, which let the operator log into accounts without needing the password at all. It grabs cryptocurrency wallet files, browser autofill data (which often includes home addresses, credit card numbers, and security recovery answers), and any credentials stored in desktop applications. Then it bundles everything into a ZIP file, sends it to the operator's server, and self-deletes. The whole process is over before the user notices anything unusual.

The output is called a stealer log. A single log is one infected machine's worth of credentials. A typical stealer log contains 30 to 200 saved passwords. The operator collects thousands of these per month and sells them in bulk to credential brokers. The brokers sort and resell them to whoever has a use — including the hacktivist crews who repackage them under a hashtag. Understanding why cleartext credentials indicate a stealer log rather than a server breach is the fastest way to read any breach claim accurately.

How they get on the laptop

Five delivery methods, in the order we see them most frequently in SA SME incidents.

Cracked software downloads. Adobe Premiere, Office activators, gaming cheats, KMS activators. These come pre-bundled with infostealers as part of the price of "free". The user accepts a Windows Defender warning, dismisses it, and the stealer is installed.

Fake browser updates. A compromised website displays a "your browser is out of date" notice that links to a fake installer. One click runs the infostealer.

Malicious search ads. Search for "download VLC", click the first paid result, and land on a near-perfect clone of the real VLC website. The download contains the stealer rather than the software.

Fake messaging app installers. WhatsApp Desktop, Telegram, Signal. Cloned installer pages are promoted via search-engine-poisoned results and paid placements.

Phishing emails with attachments. An older vector that remains effective. The attachment is usually an ISO, IMG, or ZIP file rather than a Word document, because email scanners catch the documents more reliably.

In every case, the user installed the malware themselves. Their antivirus may have warned them and they ignored it, or it did not warn them because the malware is signed with a fresh certificate that has not yet been flagged. No firewall, no SOC, and no enterprise endpoint protection on your business network was involved. The infection happened at home, on the laptop the user also brings to the office and uses to log into Office 365.

Why this is the SME problem

Three factors compound to make infostealer malware the dominant threat surface for South African small and medium businesses.

Password reuse is the norm. SABRIC and the 2025 Sophos State of Ransomware report both flagged credential-based access as the leading initial-access vector against SA mid-market organisations. The reason is straightforward: people use the same password for Gmail, Xero, the supplier portal, and their banking app. One infostealer log compromises everything connected to that password.

Personal devices touch business data. The SME laptop fleet is often a mix of company-issued machines and personal devices used for work. A staff member's spouse downloads a cracked Adobe product on the family laptop, the staff member uses that same laptop for Office 365, and the infostealer takes the work credentials along with everything else.

The MFA gap is wider than businesses realise. Most SA SMEs we audit have multi-factor authentication on the obvious accounts — Office 365 admin, banking — but not on the secondary ones: CRM, accounting software, supplier portals, internal wikis, the staff member who handles invoicing. Stealer logs include session cookies, which sidestep MFA entirely for any service that does not bind the session to the device.

What to do

Six concrete actions. Run them in order.

  1. Run a credential exposure check against your domain. Use Have I Been Pwned domain monitoring at minimum. For thorough work, use a commercial service that searches infostealer log marketplaces, not just publicly indexed breaches. You will receive a list of which work emails appear in logs and approximate dates of exposure.
  2. Force a password rotation on every flagged account. Through your identity provider. Block the old hash and set the new policy to require length and a password manager. Do not rely on asking staff to update at their convenience.
  3. Turn on phishing-resistant MFA everywhere a password unlocks money, email, or customer data. TOTP authenticator apps for the bulk of staff. Hardware keys for administrators. Treat SMS codes as a last resort rather than a first line, given the frequency of SIM swap fraud in South Africa.
  4. Invalidate all active session tokens on critical services. Stealer logs include cookies. Forcing a session reset across Office 365 and Google Workspace removes the cookie-based bypass. Do this monthly as routine practice, not only after an incident.
  5. Deploy an endpoint protection product that detects infostealer behaviour. Microsoft Defender for Business, SentinelOne, and CrowdStrike Falcon for SMEs all offer behavioural detection of stealer-family activity rather than purely signature-based file scanning. The capability matters more than the brand name.
  6. Separate personal and work devices, even informally. Instruct staff not to log into work accounts on a family laptop. The policy sounds minor until you examine the stealer log market and see that family laptops are where the majority of SME credentials originate.

If a breach does result from credential exposure, POPIA's notification obligations apply regardless of whether the original infection happened on a company device. The Information Regulator does not require forensic certainty before the notification clock starts — "reasonable grounds to believe" that personal information was accessed is the threshold.

Where Ubuntu Guard fits

We run credential exposure audits across the breach and stealer log markets and produce a single report listing the accounts in your business that are sitting in a log right now. The output is a ranked rotation list with rationale, plus a sweep of your supplier domains for the same kind of exposure — because their stealer logs become your problem when their staff log into your systems.

The next breach claim will pass. The one before it already produced the credentials that will be used against your business this quarter. The work is to find them first.

Sources

  • SABRIC: Annual Banking Crime Statistics 2025 (Published: 2026)
  • Sophos: State of Ransomware 2025 — credential-based initial access findings (Published: 2025)
  • Brinztech: Threat alert — OpSouthAfrica infostealer log analysis (Published: 25 May 2026)
  • Kaspersky GReAT: Threat intelligence analysis — Redline, Lumma, and StealC stealer families (Published: 2025–2026)
  • Have I Been Pwned: Domain monitoring service — haveibeenpwned.com

© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za

Find out which of your staff accounts are in a stealer log right now

Ubuntu Guard's credential exposure audit searches infostealer log markets, dark-web brokers, and public breach indexes for your business domain and your key suppliers. You get a ranked rotation list and a 12-month monitoring plan.

Get a Credential Exposure Audit

Questions? Reach us at [email protected]