In a remarkable surge, security researchers have documented 7.4 million devices infected with infostealer malware during the first half of 2026, representing a staggering 27% increase from the previous six months. This alarming trend was highlighted in the latest report from Flashpoint, a leading threat intelligence company, which provides essential insights derived from various underground digital ecosystems. The findings were published in their 2026 Global Threat Intelligence Report: Midyear Edition, a comprehensive document that encompasses data collected from deep and dark web forums, illicit marketplaces, encrypted communication channels, and infrastructure associated with malicious actors.
Among the most notable revelations of the report is the staggering figure of 1.7 billion credentials harvested by hackers through infostealer malware between January and June 2026. The report identifies three particularly prolific variants of infostealer malware: Vidar, StealC, and Lumma, which have emerged as the frontrunners in this malicious category. These variants have significantly amplified the threats posed to individual users and organizations alike, compelling cybersecurity experts to take renewed action.
Flashpoint characterized the current infostealer landscape as a sophisticated and fully automated threat ecosystem. The report detailed how these systems operate with minimal human oversight, functioning autonomously as credential processing engines capable of ingesting and orchestrating data at machine speed. This evolution signals a fundamental shift in how breaches are managed and executed, marking a new chapter in cybercrime.
According to Flashpoint, the evolution of infostealer malware has enabled networks of threat actors to connect directly to raw log supply chains. Once infostealer families collect sensitive data, these systems instantly ingest the stolen records, extracting valuable metadata. Subsequently, they can launch parallel credential stuffing and active session testing across numerous platforms simultaneously. This exponential increase in automation adds layers of complexity to the already intricate landscape of cybersecurity threats, making it exponentially harder for organizations to safeguard against these cyber assaults.
The report also emphasized the critical role identity now plays as an attack surface, despite the ongoing proliferation of software vulnerabilities. Flashpoint documented 21,667 vulnerability disclosures during the first half of 2026, marking an 8% increase from the preceding six months. Curiously, nearly one in five of these vulnerabilities—approximately 19%—was accompanied by public or operational exploit code. However, a troubling observation arose: only a small proportion of disclosed vulnerabilities were actively exploited. The report’s Known Exploited Vulnerabilities (KEV) catalog revealed that only 239 vulnerabilities were undergoing active exploitation during this period, a staggering 191% increase from the 82 flaws tracked by the federal CISA KEV list.
Furthermore, Flashpoint highlighted its efforts to isolate 6,808 vulnerabilities for customers before they were publicly disclosed by the National Vulnerability Database (NVD), reflecting their proactive approach to cybersecurity.
In a related context, the underground markets that facilitate the trade of infostealers and software vulnerabilities are rapidly evolving due to the proliferation of artificial intelligence (AI) threats. Over the reporting period, Flashpoint captured more than 22 million posts that were related to the malicious use of AI across illicit forums and closed chat channels. The mass accessibility of open-source AI tools has enabled many threat actors to execute local deployments without relying on public underground networks or specialized deployment services.
The report outlined how, for those still dependent on such services, AI-driven offerings tailored for cybercrime are predominantly concentrated within rapid-delivery messaging platforms and open-source infrastructures. Notably, platforms like Telegram have become hotspots for illicit communities, alongside others such as Reddit, GitHub, and Pastebin. These channels are now serving as vital distribution networks for malware, social engineering scripts, and other dangerous tools.
Additionally, Flashpoint noted a significant rise in ransomware incidents, reporting 6,256 victims in the first half of 2026—representing a staggering 45% increase compared to the previous six months. This escalation is attributed to automation, reduced costs for initial access, and a well-established ransomware-as-a-service ecosystem. Interestingly, despite the rise in attacks, there is a notable trend of fewer organizations choosing to pay ransoms, indicating a shifting attitude towards cyber extortion.
The information provided in Flashpoint’s report underscores the urgent need for organizations to reevaluate their cybersecurity measures in light of the evolving threat landscape. As the sophistication of cyber attackers continues to escalate, the importance of robust defense mechanisms becomes increasingly apparent.
