Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Lumma now leads the infostealer ecosystem in 2026, after Operation Magnus took out RedLine and META in late 2024. RedLine’s legacy footprint still surfaces in older logs, Vidar remains stubbornly durable, StealC has gained share, Atomic dominates the macOS side, and ACR Stealer and Meduza are the rising Russian-language contenders. The top six families together produce the overwhelming majority of all stealer logs traded in 2026. Here is who is in your stealer log and why each one matters. Ransomnews Research Team. Window: post-Operation Magnus through May 2026.

Read More

A stealer log is the data dump that an infostealer malware produces after it compromises a device. It typically contains every saved browser password, every active session cookie, autofill data, system details, and in some families, screenshots and clipboard history. Stealer logs feed account takeover, ransomware initial access, and corporate breach pipelines. This explainer covers what a 2026 stealer log actually holds, how devices end up in one, how the logs are sold, and how anyone can check whether their data is in the ecosystem. Ransomnews Research Team. Updated June 2026.

Read More