The stealer ecosystem has matured into a professionalized criminal economy that most organizations are simply not monitoring closely enough.
While the industry fixates on household names like Lumma and RedLine, a growing class of lesser-known, actively deployed stealers, Void, a C++ infostealer that emerged in late 2025, Datura, Misericorde, Saturn, and others, are quietly collecting credentials, session cookies, and crypto wallet data from victims worldwide, feeding logs into underground markets that fuel ransomware, account takeovers, and business email compromise.
In a just-released research report The Unknown Stealers: From Dark Web to Log Markets, SOCRadar researchers identify up to six simultaneous active campaigns running on the Void infrastructure. Each campaign used slightly modified binaries, a natural artifact of different affiliates configuring their own builds, but all shared the same underlying C2 relay architecture and Steam-based resolution mechanism. Some Steam accounts used in earlier campaigns had already been deleted, indicating active infrastructure rotation. Void is a textbook example of how low-profile, under monitored stealers can operate at scale before anyone is paying attention.
You can read the research report here: https://socradar.io/resources/whitepapers/stealer-dark-web-log-markets
Related
This entry was posted on April 13, 2026 at 1:52 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
SOCRadar Puts Out A Research Report On The Stealer Ecosystem
The stealer ecosystem has matured into a professionalized criminal economy that most organizations are simply not monitoring closely enough.
While the industry fixates on household names like Lumma and RedLine, a growing class of lesser-known, actively deployed stealers, Void, a C++ infostealer that emerged in late 2025, Datura, Misericorde, Saturn, and others, are quietly collecting credentials, session cookies, and crypto wallet data from victims worldwide, feeding logs into underground markets that fuel ransomware, account takeovers, and business email compromise.
In a just-released research report The Unknown Stealers: From Dark Web to Log Markets, SOCRadar researchers identify up to six simultaneous active campaigns running on the Void infrastructure. Each campaign used slightly modified binaries, a natural artifact of different affiliates configuring their own builds, but all shared the same underlying C2 relay architecture and Steam-based resolution mechanism. Some Steam accounts used in earlier campaigns had already been deleted, indicating active infrastructure rotation. Void is a textbook example of how low-profile, under monitored stealers can operate at scale before anyone is paying attention.
You can read the research report here: https://socradar.io/resources/whitepapers/stealer-dark-web-log-markets
Share this:
Like this:
Related
This entry was posted on April 13, 2026 at 1:52 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.