Infostealer Malware Persists Through Failed Disruptions, Infects 394K Systems in 2026

Law enforcement disruptions of Lumma and StealC delivered partial victories but exposed how decentralized cybercrime networks rapidly reconstitute their operations.

Infostealer malware continues to infect hundreds of thousands of Windows computers despite high-profile law enforcement disruptions, demonstrating the resilience of organized cybercrime networks. Between March and May 2025, Microsoft’s Digital Crimes Unit identified 394,000 Windows computers globally infected with Lumma Stealer, one of the most prolific password-stealing tools in operation. Even after Microsoft obtained a court order on May 13, 2025, and seized approximately 2,300 malicious domains associated with the malware’s infrastructure, Lumma’s operators resumed their campaigns within days—showing that dismantling the infrastructure behind these attacks leaves the fundamental threat intact. The persistence of infostealer malware reveals a structural problem in how cybercriminals organize their operations. Unlike traditional malware families with centralized control, modern infostealers operate through decentralized affiliate networks where independent operators license the malware, deploy it through their own channels, and share profits with authors.

When law enforcement takes down one infrastructure, the operators simply rebuild elsewhere, making disruption efforts feel like squeezing water through a clenched fist. A year later, in June 2026, Microsoft coordinated another major takedown targeting StealC and Amadey infostealers, shutting down over 100 criminal servers and seizing 24 million stolen credentials—yet the underlying problem persists. The breadth of the threat extends far beyond any single disruption campaign. Throughout 2025, infostealers harvested approximately 1.8 billion credentials across roughly 5.8 million infected devices worldwide, according to analysis of stolen data markets. This scale illustrates why isolated takedowns, while important for law enforcement accountability and disrupting specific criminal operations, cannot reverse the larger trend of compromised credentials flooding underground markets.

Table of Contents

How Do Infostealer Operators Reconstitute Networks After Major Disruptions?

The speed at which Lumma Stealer operators came back online after Microsoft’s May 2025 takedown shocked some observers, but it revealed a fundamental truth: the malware-as-a-service model makes the infrastructure less important than the operators distributing it. When Microsoft seized 2,300 malicious domains and redirected another 1,300 to law enforcement sinkholes for monitoring, the takedown disabled a significant portion of Lumma’s command-and-control infrastructure. But the operators who profited from deploying Lumma to victims had their own customers, their own distribution networks, and their own financial incentives to keep operating. Within days, they were renting new server space, registering new domains, and selling access to the malware again.

This decentralized model is fundamentally different from disrupting a single cybercriminal or criminal organization with a clear hierarchy and central point of control. In Lumma’s case, investigators found that different affiliate operators were independently spreading the malware to victims through spam campaigns, exploit kits, and compromised websites. Some affiliates might have lost their access when their command-and-control servers were seized, but others maintained redundant infrastructure. The criminal marketplace quickly redistributed tasks among remaining operators, each running their own slice of the business with their own recovery plans already in place. This architecture exists by design—every operator knows that seizure is an occupational risk, and most have already planned for the day their primary infrastructure disappears.

The Scale of Infostealer Infections Continues to Grow Despite Takedowns

The 394,000 systems infected with Lumma Stealer between March and May 2025 represented only a portion of the total infostealer problem captured by incident responders and security researchers. Four months later, when Microsoft and its partners targeted StealC and Amadey infostealers, they identified 140,000 or more infected computers that had been compromised in just the first two weeks of May 2026. Combined, these two major disruptions affected over 534,000 systems across the 2025-2026 timeline—yet this figure likely undercounts actual infections, since many victims never detect that they’ve been compromised and infected systems often go unreported. Broader statistics from credential theft monitoring reveal the actual scope of the problem.

In 2025 alone, approximately 5.8 million devices were infected with infostealer malware, generating the theft of 1.8 billion credentials. These numbers come from monitoring of underground data markets, where stolen credentials are catalogued, indexed, and resold by criminal groups. The sheer volume means that even the most sophisticated organizations cannot monitor all compromised credentials in real time. A significant limitation of these statistics is that they rely on what criminals actually expose for sale in markets researchers can access—the true number of stolen credentials is certainly higher, including internal theft by actors who monetize breaches without advertising them publicly.

StealC Credential Theft and Law Enforcement RecoveryCredentials Stolen30000000 credentialsCredentials Recovered24000000 credentialsCredentials Lost to Criminals6000000 credentialsSource: Microsoft Security Blog

The Lumma Stealer Takedown: Why a Partial Victory Wasn’t Enough

On May 13, 2025, Microsoft filed legal action against the operators and infrastructure supporting Lumma Stealer and obtained a court order from the U.S. District Court in the Northern District of Georgia. The agency then coordinated with hosting providers, domain registrars, and law enforcement agencies globally to seize approximately 2,300 malicious domains directly associated with the malware’s command-and-control infrastructure. An additional 1,300 domains were redirected to Microsoft sinkholes—servers controlled by law enforcement—to allow monitoring of ongoing attack attempts and identification of victims still trying to communicate with malicious infrastructure they didn’t know had been disrupted. By most measures, this was a significant law enforcement victory.

The takedown removed a large portion of Lumma’s operational capacity, disrupted ongoing campaigns, and gave investigators visibility into the scope and techniques used by operators. However, the victory proved incomplete. Within days of the takedown, researchers reported that Lumma activity had spiked post-disruption, indicating that operators were not only reconstituting their infrastructure but actively escalating their campaigns. This suggests that rather than deterring criminal activity, the disruption may have motivated operators to work faster and more aggressively to recover their lost revenue before additional law enforcement pressure arrived. The lesson is clear: disruption alone does not eliminate the threat or change the incentive structure that makes infostealer malware profitable.

StealC and Amadey’s 2026 Takedown and the Question of Distributed Infrastructure

Microsoft’s June 24, 2026 takedown of StealC and Amadey infostealers, conducted through what the agency called “Operation Endgame,” represented an escalation in law enforcement coordination and tactics. Rather than targeting a single malware family, the operation targeted a coordinated pair of threat actors and their infrastructure: Amadey, which functions as a loader for initial system compromise, and StealC, which harvests credentials and other sensitive data for monetization. By taking down both pieces of the pipeline simultaneously, investigators aimed to disrupt the entire criminal operation rather than just damage one component. The coordination required to identify, track, and dismantle multiple interconnected operations across international borders reflects years of investigation and intelligence sharing among agencies. The scale of what was seized reflects the resources devoted to this operation. Law enforcement identified and shut down over 200 malicious command-and-control domains and IP addresses, seized 100 or more criminal servers and domains, and recovered 24 million stolen login credentials that had already been extracted from victims’ systems.

Additionally, cryptocurrency exchange accounts associated with the operation were frozen with €41 million (approximately $46.5 million USD) in assets seized. These numbers represent a substantial blow to the criminals’ immediate ability to operate, though the frozen cryptocurrency and seized credentials still required distribution through legitimate-looking sale channels, suggesting that the most valuable assets—active victim access and yet-to-be-discovered vulnerabilities—remained with the operators. Between July 4, 2025 and June 16, 2026, StealC had stolen a total of 30 million credentials from infected systems. Of these, law enforcement recovered 24 million during the takedown and subsequent investigations. The 6 million credentials that were not recovered—a 20 percent loss—were already sold, distributed, or deleted by the criminals before law enforcement gained access to the infrastructure. This means that hundreds of thousands of individuals whose credentials were stolen face an unknown and potentially permanent leak of their passwords, security questions, and other authentication factors to actors on underground markets. The limitation of any takedown is that some damage is irreversible by the time authorities can act.

The Broader Credential Theft Problem: 1.8 Billion Accounts at Risk

When placed in the context of the overall infostealer ecosystem, the individual disruptions of Lumma, StealC, and Amadey represent partial responses to a massive, distributed problem. Across 2025, approximately 1.8 billion credentials were stolen by infostealer malware and captured by security researchers monitoring underground markets. This figure comes from analysis by Shattered.io, an organization that tracks compromised data, and represents credentials stolen across approximately 5.8 million infected devices worldwide. That means an average of 310 credentials were stolen per infected device—including passwords for email accounts, social media, banking, cryptocurrency wallets, and internal corporate systems.

The persistence of massive credential theft numbers despite major law enforcement actions reveals that disruption campaigns are treating a symptom rather than addressing the root cause. As long as there is a market for stolen credentials and a market for the malware itself, operators will continue to develop, deploy, and profit from infostealers. The 1.8 billion credentials stolen in 2025 represent real harm to individuals and organizations: account takeovers, identity theft, corporate espionage, and ransomware attacks enabled by compromised credentials. A warning for organizations is that even companies protected by sophisticated endpoint detection and response systems can still fall victim if their employees visit a compromised website or download a malicious file, especially if they lack browser isolation and advanced browser security features.

Following the Money: Why Asset Seizures Don’t Stop the Crime

The €41 million in cryptocurrency assets frozen during Operation Endgame illustrates law enforcement’s evolving approach to disrupting the financial incentives behind organized cybercrime. By tracing cryptocurrency transactions and working with exchanges to freeze accounts before criminals could convert their holdings into harder-to-trace forms, authorities attempted to strike directly at the profit motive. Yet this approach has inherent limitations. Sophisticated criminal groups use mixing services, atomic swaps across blockchains, and money laundering through legitimate businesses to obscure and eventually spend their cryptocurrency. A €41 million seizure is significant, but a criminal organization that has stolen billions of credentials can recover that loss through a few weeks of intensive credential harvesting and resale.

The business model of credential resale is remarkably efficient. Stolen credentials are advertised in underground forums with information about what access they provide—email credentials worth more if the account has saved payment methods, banking credentials worth more if confirmed to be active, corporate credentials worth premiums if they provide access to valuable networks. Prices range from pennies for low-quality credentials to hundreds of dollars for administrative access. When an operator has harvested millions of credentials, they can cover a €41 million loss and fund the development of new malware variants and tactics within weeks. The comparison to drug trafficking is apt: seizing product disrupts supply temporarily but doesn’t eliminate demand or the underlying criminal organization.

The Structural Challenge of Decentralized Cybercrime Networks

The recurring pattern of infostealer disruptions—successful takedown followed by rapid reconstitution—reveals a structural problem in law enforcement’s approach to cybercrime. Modern malware-as-a-service networks are explicitly designed to survive the loss of individual operators, domains, or infrastructure components. When Lumma Stealer’s operators resumed operations within days of Microsoft’s seizure of 2,300 domains, they were able to do so because their business model already accounted for domain takedowns. Similarly, when StealC and Amadey were disrupted, the underlying creators of the malware retained the code, and new operators renting or acquiring the tools began deploying them within weeks.

The threat from infostealer malware will persist as long as the three enabling conditions remain in place: a large pool of vulnerable, unpatched endpoints; reliable distribution channels for the malware; and accessible underground markets for selling stolen credentials. Law enforcement can disrupt each of these—by improving system security, preventing malicious file distribution, and shutting down criminal marketplaces—but doing so simultaneously across the global internet remains impractical. The criminals are also adapting faster than defenses. Each major disruption of an infostealer family teaches the criminal ecosystem valuable lessons about what signatures and infrastructure patterns law enforcement can detect, allowing the next generation of malware to evade detection more effectively. By the time Microsoft shut down 24 million stolen StealC credentials in June 2026, other infostealer families including Vidar, Redline, and derivative variants were already expanding their presence in the same underground markets.

Frequently Asked Questions

If 394,000 systems were infected with Lumma Stealer, why did the takedown happen in May 2025?

The 394,000 figure represents systems infected between March 16 and May 16, 2025. Microsoft’s Digital Crimes Unit tracked the infections, obtained a court order on May 13, 2025, and executed the takedown shortly after. Detection and attribution of infostealer infections takes weeks, so the formal disruption came several months into the active infection period.

What’s the difference between StealC and Amadey if they were both disrupted together?

Amadey functions as a loader—malware that gains initial access to a system and downloads additional payloads. StealC is the stealer payload that Amadey deploys, responsible for harvesting credentials and other sensitive data. Together they form a complete attack pipeline, which is why disrupting both simultaneously was more effective than targeting either one alone.

How much harm does credential theft actually cause if most accounts have two-factor authentication?

Two-factor authentication protects against many attacks but not all. Criminals with stolen credentials can attempt account takeovers, sell credentials to other criminals for targeted attacks, and use the information for social engineering. Additionally, many victims don’t enable two-factor authentication or use less-secure forms like SMS, which can be bypassed. For organizations, compromised credentials can lead to lateral movement within networks and ransomware attacks.

If law enforcement recovered 24 million StealC credentials, shouldn’t victims be notified?

Many victims were notified through data breach notification channels, but law enforcement and private sector coordination on victim notification remains inconsistent globally. Some victims may never learn that their credentials were compromised and recovered. There is no unified system for cross-border credential breach notification, which is a limitation of current incident response protocols.

Why do infostealers remain profitable if so many are being disrupted?

1.8 billion credentials stolen in 2025 across 5.8 million devices represents enormous revenue potential. Even after accounting for takedowns and credential market saturation, the volume of theft is so large that criminals can continue operations profitably. Additionally, new operators constantly enter the market, new malware variants are developed, and each disruption simply eliminates competition rather than reducing overall demand for stolen credentials.

Will law enforcement ever completely stop infostealer malware?

No single disruption campaign will eliminate infostealers while vulnerable systems exist and credentials remain valuable. Long-term reduction requires improvements in endpoint security, browser isolation technology, safer authentication methods beyond passwords, and global coordination on detection and takedowns. Individual operations like the Lumma and StealC disruptions are important for accountability and short-term damage but are unlikely to reverse the underlying trend of credential theft at scale. —


You Might Also Like