Find notable cyber news and cases, enriched with sources, timelines, and signals.

Infostealer malware H1 2026 credential-harvesting surge

Malware Activity
First reported
Last updated
Happening score
H score 70
1 unique sources, 1 articles

Summary

Hide ▲

Threat intelligence researchers recorded a 7.4 million-device infostealer surge in H1 2026, and the activity drove theft of 1.7 billion credentials. Vidar, StealC, and Lumma were the most prolific variants in the period. The shift turned infostealers into a high-volume credential-harvesting pipeline that increases downstream account-abuse risk.

Related Happenings

Formula 1 fan scam ecosystem campaign

Campaign
H score34 First: 25.05.2026 12:00 Last: 25.05.2026 12:00 Sources 1

About this happening: A coordinated scam ecosystem is targeting Formula 1 fans with fake streaming apps, counterfeit merchandise, and social-media lures, creating theft, fraud, and malw...

Infostealer malware operation targeting online store users

Malware Activity
H score32 First: 21.05.2026 00:36 Last: 21.05.2026 00:36 Sources 1

About this happening: A malware operation using infostealer tools infected users’ devices between 2024 and 2025, stealing browser sessions and account credentials that enabled account theft...

REMUS infostealer browser-session and password-manager collection expansion

Malware Activity
H score21 First: 15.05.2026 17:02 Last: 15.05.2026 17:02 Sources 1

About this happening: REMUS expanded its session-theft and password-manager collection capabilities, increasing the malware’s ability to capture authenticated access and browser-side data....

2025 Global cybercrime surge across credentials, ransomware, DDoS, and KEV exploitation

Trend
H score89 First: 29.04.2026 16:00 Last: 29.04.2026 16:00 Sources 1

About this happening: In 2025, global cybercrime activity intensified across compromised credentials, ransomware, DDoS, and KEV exploitation, raising risk for organizations worldwid...

Vidar infostealer market rise and distribution expansion

Malware Activity
H score30 First: 28.04.2026 22:07 Last: 28.04.2026 22:07 Sources 1

How related: In total, it claimed that hackers harvested 1.7 billion credentials via infostealer malware between January and June 2026, with Vidar, StealC and Lumma the top three most prolific infostealer variants.

About this happening: Vidar remains a long-running infostealer threat, with Aryaka reporting a fresh Windows campaign in recent weeks that used a PowerShell infection chain, the...

Timeline

  1. 17.08.2026 10:30 2 articles · 2h ago

    Infostealer malware H1 2026 credential-harvesting surge

    Initial Disclosure

    Researchers first saw infostealer activity accelerate across endpoints and credential stores in early 2026. The initial surge was dominated by Vidar, StealC, and Lumma while overall theft volume climbed sharply.

    Show sources