Stealer-log markets after the Lumma takedown wave: Russian Market fills the vacuum
When authorities disrupted the Lumma Stealer and Rhadamanthys operations during 2025, some observers predicted a quiet year for stealer logs. The opposite happened. The commodity simply moved to whoever was still open for business, and one marketplace absorbed most of the displaced traffic.
Russian Market becomes the dominant shelf
Analysis by DarkOwl shows that after the takedown pressure on competing platforms, Russian Market emerged as the dominant venue for stolen log sales, listing more than 180,000 stealer logs in the first half of 2025 alone. Unlike full-service darknet markets, it functions as a narrow storefront: no escrow theater, no forum debates, just searchable inventory of credentials harvested from infected machines, sold for dollars per batch. The scale matters less than the composition. ReliaQuest examined what buyers actually get when they purchase from these shelves and found that 77 percent of logs sold on Russian Market contained single sign-on tokens or active session cookies, not merely passwords. That distinction reshapes the threat model entirely: a reused password can be defeated by multi-factor authentication, but a valid session token walks straight past it. Why session tokens beat passwords
An SSO token or session cookie is a shortcut past the front door. Attackers import it into their own browser using cookie-editing extensions, inherit an already-authenticated session, and bypass login prompts, MFA challenges, and step-up verification in one motion. For enterprises federating identity across hundreds of services through a single provider, one harvested token can equal broad access with no alarm raised at any perimeter. This is why infostealers became such a lucrative product line despite cheap subscription pricing. The malware itself is disposable; the tokens it collects are the real inventory. By some industry counts, infostealers harvested roughly 1.8 billion credentials during 2025, a volume that keeps resale prices low while keeping supply effectively unlimited. The malware churn continues underneath
Takedowns reshuffled distribution but did not retire the loaders. Flashpoint reported that by January 2026, Vidar 2.0 had become the most-used stealer in circulation, inheriting users from disrupted families. AhnLab's ASEC team documented the parallel picture on the distribution side in February 2026, observing that LummaC2, ACRStealer, StealC, and Vidar dominate current infostealer delivery through cracked software sites, malvertising, and phishing attachments. Notably, Lumma persists as a brand even after its infrastructure was disrupted, a reminder that malware-as-a-service operations rebuild faster than press releases imply. The 48-hour window
Verizon's DBIR analysis added the detail that should worry defenders most: 54 percent of ransomware victims had domain credentials circulating in stealer logs before the attack, and in some cases only about 48 hours elapsed between a log appearing for sale and the intrusion it enabled. The kill chain has compressed to the point where quarterly credential monitoring is functionally useless. If a domain admin's session token goes on sale Monday, the ransomware crew may be inside by Wednesday. That speed also explains why stealer logs have become upstream infrastructure for other criminal markets. Initial access brokers buy fresh logs, filter them for corporate VPN portals and identity providers, then resell verified access to ransomware affiliates. A ten-dollar log purchase can cascade into a multimillion-dollar extortion event within the same week. What this means for anyone watching underground markets
The lesson tracks with what we covered in our piece on market lifespan economics: individual platforms are fragile, but demand outlives every seizure. Takedown Lumma and Vidar tops the charts; shutter one storefront and Russian Market absorbs the listings. Law enforcement actions raise costs and create churn, yet they have never eliminated a commodity that regenerates at the endpoint level, one infected browser at a time. For organizations, the practical responses remain unglamorous but effective: shorten session lifetimes for privileged accounts, require phishing-resistant reauthentication for sensitive systems, treat cookie theft as a first-class attack vector rather than an afterthought, and monitor stealer-log exposure continuously rather than on audit cycles. For individuals, the old hygiene rules hold — unique passwords, hardware-backed MFA where possible, and healthy suspicion of cracked software, which remains the top infection channel per ASEC's observations. Stealer logs are no longer a niche curiosity on the underground; they are the raw material feeding the most expensive attacks of the era. Watch this category closely, because the storefronts will keep changing names while the pipeline behind them stays busy.