1 in 20 Stealer Log Victims are Threat Actors

August 19, 2026

By Andréanne Bergeron, Security Researcher

When analysts examine stealer logs, the underlying assumption is that each infected device belongs to a victim. However, cybercriminals are not immune to the same operational mistakes as everyone else. They test malware, exchange stolen data, manage infrastructure, and therefore, occasionally become infected themselves. As a result, the same datasets that document victimization may also contain traces of the threat actors responsible for the attacks. Our analysis shows that approximately 5% of the sampled infections exhibit behavioral profiles consistent with threat actor activity.

Key Findings About Threat Actor Stealer Log Victims

  • Approximately 5% of infected devices exhibited behavioral patterns consistent with threat actor activity, suggesting that infostealer datasets contain not only victims but also cybercriminals themselves.
  • No single behavior identifies a threat actor. Instead, multiple independent behavioral signals become significantly more informative when they occur together on the same device.
  • Stealer logs represent an underused source of threat intelligence. Beyond exposing compromised organizations, they can also help identify the operational footprints of the attackers behind cybercrime.
Flare CTA Block Preview

Identity Intelligence

Turn Stealer Logs Into Actionable Threat Intelligence

Stealer logs reveal more than compromised credentials as they expose the operational behaviors of threat actors themselves. Flare continuously collects and enriches infostealer data from dark web markets and illicit Telegram channels, giving your team the visibility to detect organizational exposure and investigate adversary activities in the same dataset.

Search and pivot across billions of stealer log records with full behavioral context
Detect your organization’s exposed credentials and sessions as soon as they surface
Start Free Trial

Building the Dataset

To investigate whether infostealer logs contain traces of threat actors alongside their victims, we analyzed a dataset of 10,200 infostealer logs collected throughout 2025. Rather than focusing on a single campaign or malware family, we sought a broad snapshot of compromised devices observed over the course of an entire year. We therefore constructed the dataset by randomly sampling thirty stealer logs per day, resulting in a collection spanning a wide range of malware families, countries, and victim profiles.

Although these logs primarily represent infected users, our objective was to determine whether some of them exhibited behavioral patterns more consistent with threat actors than with ordinary victims. Because no ground truth exists to answer this question directly, we relied on observable behaviors that have been repeatedly associated with cybercriminal activity in prior threat intelligence research.

From Isolated Behaviors to Behavioral Patterns

To characterize behaviors commonly associated with cybercriminal activity, we identified 10 behavioral signals based on previous threat intelligence research and common operational practices. These signals capture activities ranging from visits to underground communities and malware distribution websites to interactions with cryptocurrency services, suspicious network behavior, and indicators of infrastructure management. Below is a summary of the 10 signals together with the proportion of devices in our dataset exhibiting each behavior.

Individually, none of these signals is sufficient to identify a threat actor. Many have perfectly legitimate explanations, while others are simply uncommon rather than inherently malicious. Our objective was therefore not to identify a single “smoking gun,” but to determine whether several independent indicators occurring on the same device collectively suggest behavior that is atypical of ordinary victims. Importantly, such patterns do not necessarily indicate malicious intent. Similar combinations of activities may also be observed on the devices of threat intelligence analysts, security researchers, penetration testers, or other cybersecurity professionals whose work involves interacting with adversarial infrastructure or tools. Consequently, the methodology should be viewed as a prioritization mechanism that identifies devices warranting further investigation, rather than a definitive means of attributing a device to a threat actor.

Each behavior is recorded simply as present or absent. Whether a user visited a cryptocurrency exchange once or fifty times is less informative than whether cryptocurrency activity co-occurs with several other behaviors associated with threat actor operations. This design also prevents a single extreme behavior from dominating the score.

When Does an Infected Device Become Suspicious?

The next challenge was determining how many behavioral signals should be present before a device warrants further attention. Devices exhibiting only one signal were common and generally indistinguishable from ordinary users. Devices exhibiting two signals already appeared considerably more suspicious, with combinations of behaviors that were often difficult to reconcile with everyday computer use.

Nevertheless, our objective was not to identify every potentially suspicious device, but rather to minimize false positives. Below is the distribution of devices according to the number of signals they exhibit.

The value emerges when these behaviors co-occur on the same device. Rather than looking for a single “smoking gun,” we look for the accumulation of multiple independent indicators that, together, become increasingly difficult to explain through ordinary computer use. This follows a principle familiar to both criminology and intelligence analysis: individual clues may be weak evidence, but several independent clues pointing in the same direction can substantially increase confidence.

The Two-Signal Threshold: Informative but Still Ambiguous

We closely examined the devices exhibiting two behavioral signals with in mind that not all combinations are equally informative. For example, a device that accesses cryptocurrency platforms and occasionally visits the dark web may still reflect legitimate or ambiguous activity. In contrast, in this sample, the observation was that in most cases, the combination of signals already appeared more suspicious than would typically be expected from ordinary users. For example, a device that visits malware distribution websites while also interacting with an unusually large number of private network segments presents a behavioral pattern that is considerably more difficult to explain through benign use.

The Three-Signal Threshold: Conservative and Actionable

Manual examination of the cases exhibiting two behavioral signals frequently identified cases that appeared to be genuine threat actors rather than cybersecurity professionals. Nevertheless, to minimize false positives and ensure a highly conservative methodology, we required at least three independent behavioral signals before classifying a device as a potential threat actor. Approximately 5% of infected devices in our sample satisfied this criterion.

Recommendation for Security Teams

Expand the role of infostealer intelligence beyond exposure monitoring. Behavioral analysis can transform these datasets into a proactive intelligence source, helping organizations identify emerging threat actors and better understand the cybercriminal ecosystem.

Infostealers Capture Threat Actors Too

One of the most striking findings is that approximately 5% of the infected devices in our sample exhibited a behavioral profile consistent with threat-actor activity. This suggests that infostealer datasets may contain far more than just victims. They may also capture a non-negligible population of the individuals involved in cybercrime operations themselves.

This observation is consistent with a long-standing finding in criminology known as the victim–offender overlap. Individuals involved in offending are often more likely to experience victimization themselves. Research across multiple crime types has shown that engagement in criminal or deviant activities can increase exposure to situations, environments, and relationships where victimization becomes more likely.

The findings reinforce an important (and often overlooked) reality of the cybercrime ecosystem: threat actors also get infected. Whether through poor operational security, testing malware on their own machines, or becoming victims of competing malware, cybercriminals are not immune to the same threats they create. As a result, infostealer datasets should not be viewed solely as collections of victims, but also as a potential source of intelligence on the attackers themselves.

Flare CTA Block Preview

Identity Intelligence

Turn Stealer Logs Into Actionable Threat Intelligence

Stealer logs reveal more than compromised credentials as they expose the operational behaviors of threat actors themselves. Flare continuously collects and enriches infostealer data from dark web markets and illicit Telegram channels, giving your team the visibility to detect organizational exposure and investigate adversary activities in the same dataset.

Search and pivot across billions of stealer log records with full behavioral context
Detect your organization’s exposed credentials and sessions as soon as they surface
Start Free Trial
Share article