Sherlog2026-06-24 · 2 min read

Anatomy of a stealer log: from infection to sale in 31 hours

We followed a single log batch from the moment it hit a Telegram channel to the moment its credentials were tested against a corporate VPN. The window is smaller than you think.

A stealer log is not a data breach in the way most security teams imagine one. There is no perimeter event, no exfiltration alarm and no vendor notification. An employee installs a cracked utility on a personal laptop, and forty seconds later every saved password, session cookie and autofill record on that machine is packaged into an archive and shipped to a collection channel.

We traced one such batch, anonymized and with the victim organization's consent, through its full lifecycle. Collection at 03:12. First listing in a subscription channel at 03:40. Indexed by our pipeline at 03:19, between those two events. First credential-stuffing attempt against the victim's VPN gateway: 10:07 the following morning. Total time from infection to hostile use: 31 hours.

INFECTION → HOSTILE USE · 31 HOURS

one batch, anonymized
first 40 min widened for legibility ·⫽· then ~30 h03:12 · CAPTURED IN CHANNEL03:19 · INDEXED & ALERTING03:40 · LISTED FOR SALE10:07 +1D · CREDENTIALS TRIED AT THE VPNTRIPWIRE AT THE COLLECTION CHANNEL30 H 48 M OF WARNINGTRIPWIRE AT THE VPN GATEWAY0 H · THE ATTEMPT IS THE ALARM
FIG. 01 · one traced batch, capture to hostile use. The tripwire placement is the whole economics.

The operational lesson is about where you place your tripwire. Detection at the VPN gateway gives you zero hours of warning, because the attempt is the alarm. Detection at the collection channel gives you the full 31. That gap is the entire economics of credential abuse, and it is why "we monitor for breaches" and "we monitor collection channels" are different capabilities that happen to share a marketing category.

One more number worth sitting with: 14 of the records in that batch carried session cookies that were still valid at index time. A password reset closes one door. The sessions minted before the reset walk through another. We measured that window separately.

RELATED PAPERSession cookies outlive password resets: measuring the window

The Sherlog research desk

Written from primary sources. No third-party feed was harmed.

See Sherlog

Keep reading

This paper is what we publish.

The platform is what we keep.

NDA-friendly briefings · global coverage · no slideware