Credential harvesting
The collection stage of an operation, separate from its use: gathering usernames and passwords at scale through phishing pages, infostealers, compromised forms or scraped breaches, with no immediate intention of logging in.
Why it matters to you
The gap between harvest and use is the whole opportunity. Credentials are collected long before anyone tries them, often by a different party entirely, so watching for failed logins finds you the end of the process and never the middle. Watch for your domain appearing in collections instead.
Where we meet it
Harvesting and exploitation are different jobs done by different people. The harvester sells in bulk and moves on, which is why a set of credentials can surface in several unrelated campaigns months apart.
Connected terms
Infostealer
Commodity malware that runs once on a machine, empties every credential store it can reach, and leaves. Browser passwords, session cookies, crypto wallet files, VPN and messaging configs, then a screenshot and a file listing. The output is a stealer log.
Combolist
A recycled email:password list compiled from old breaches and other people's logs, resold in bulk. The fast food of the credential economy: cheap, stale, everywhere.
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Traffer
The distribution worker of the stealer economy: drives victims to infected downloads via malvertising, fake installers, cracked software and phishing. Organized into teams with quotas and payout shares.
Where this term stops being vocabulary
Sherlog is where you watch it happen to you
Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.
More from the playbook
Adversary-in-the-middle phishing
A phishing page that proxies the real login instead of imitating it. The victim authenticates against the genuine site through the attacker's server, completes multi-factor as normal, and the attacker keeps the resulting session cookie.
Business Email Compromise (BEC)
Fraud committed from inside a real mailbox: the attacker reads the thread, waits for an invoice and answers it with different bank details. No malware, no attachment, nothing for a scanner to find.
Callback phishing
An email that carries no link and no attachment, only a plausible invoice or subscription notice and a phone number to dispute it. The attack begins when the victim calls, and the person who answers walks them into installing remote access software.
Checker
A tool that tests stolen credentials against a target service in bulk and sorts the live ones from the dead. The industrialized step between a combolist and an account takeover.