PHILADELPHIA, PA — Credentials stolen by infostealer malware can remain usable for months or years after an infected device is cleaned, extending an organization’s exposure beyond the initial attack, according to research published this week by Specops Software, an Outpost24 company.
The findings put the focus on credentials left behind after remediation rather than solely on eliminating the malware. Infostealers can extract saved passwords, session cookies, cloud keys, and source-code credentials from browsers, local folders, and developer tools before transmitting the data to attacker-controlled infrastructure.
Once stolen, those credentials can circulate independently of the original infection. Specops said access to infostealer malware is sold on criminal forums for as little as $120 a month, while stolen credential logs can sell for about $10 to more than $100 depending on their perceived value.
The research cited Lumma, RedLine, Vidar, and Raccoon among malware families designed to collect authentication data.
The persistence of stolen credentials has surfaced in previous attacks. Specops cited Mandiant research finding that at least 79.7% of accounts used in the 2024 Snowflake attacks had credentials exposed beforehand, with some linked to infections dating to November 2020.
That lag illustrates how credential exposure can survive long after an organization considers the original endpoint infection resolved.
“Removing the malware ends the infection, but not the exposure,” Darren James, senior product manager at Specops Software, said. He said compromised passwords need to be changed, stolen sessions revoked and access from untrusted devices restricted.
Stolen sessions can also weaken the protection offered by multifactor authentication. “If an attacker has a valid session, MFA alone may not stop them,” James said.
The research also pointed to an August 2026 Australian enforcement action involving two men charged over their alleged involvement with TeamPCP. The group has been linked to supply-chain attacks targeting GitHub projects and harvesting Amazon Web Services keys and API tokens, according to the release.
The Australian Federal Police said the wider campaign potentially affected more than 1,000 organizations and exposed more than 500,000 credentials, according to Specops.
Specops published the research as it added more than 46 million newly compromised passwords to its Breached Password Protection service, using data gathered through its honeypot network and threat-intelligence sources that include infostealer-log monitoring.
The service checks Active Directory passwords against a database containing more than 6 billion compromised passwords and updates the database daily, according to the company.
Specops, part of Sweden-based cybersecurity company Outpost24, provides password-security and identity-management services. The company says its products are used by more than 3,000 organizations across 65 countries. More information is available at specopssoft.com.
Support the local news that supports Chester County. MyChesCo delivers reliable, fact-based reporting and essential community resources—free for everyone. If you value that, click here to become a patron today.
