π¦ 11.1 million devices. 3.3 billion stolen credentials. One $60 subscription.
That's the infostealer economy in 2025.
Infostealer malware is now sold as a monthly subscription starting at $60 and it gives attackers every saved password, session cookie, and crypto wallet key on your device within minutes of infection. No brute force. No phishing link you have to click twice. Just a silent harvest and a log posted to criminal markets within 24β72 hours.
The five families behind 11 million infections in 2025: Lumma, Acreed, Rhadamanthys, Vidar, StealC. By early 2026 Vidar alone accounts for 73% of infected hosts.
And it's not just account takeover. Stolen VPN and RDP credentials are how ransomware gets inside the perimeter as a legitimate logged-in user, weeks before the attack fires.
The 24β72 hour window between infection and log publication is the only moment to act. https://hashnode.com/edit/cmqau7g5y000204l86uka8o36
That's the infostealer economy in 2025.
Infostealer malware is now sold as a monthly subscription starting at $60 and it gives attackers every saved password, session cookie, and crypto wallet key on your device within minutes of infection. No brute force. No phishing link you have to click twice. Just a silent harvest and a log posted to criminal markets within 24β72 hours.
The five families behind 11 million infections in 2025: Lumma, Acreed, Rhadamanthys, Vidar, StealC. By early 2026 Vidar alone accounts for 73% of infected hosts.
And it's not just account takeover. Stolen VPN and RDP credentials are how ransomware gets inside the perimeter as a legitimate logged-in user, weeks before the attack fires.
The 24β72 hour window between infection and log publication is the only moment to act. https://hashnode.com/edit/cmqau7g5y000204l86uka8o36
Hashnode
Hashnode is a blogging platform where developers, engineers, and tech leaders write to sharpen ideas, share knowledge, and build their reputation. Start for free.
π¨ OnyxC2: $250/month buys everything on your employees' devices
A new Malware-as-a-Service platform evades 71 antivirus engines on first run and harvests 4,717 cookies, 55 passwords, and active session tokens from a single machine β in one pass.
The stolen VPN credentials it lifts are how ransomware gets in weeks later.
Full breakdown β https://relayshield.hashnode.dev/onyxc2-when-250-month-buys-everything-on-your-employees-devices?utm_source=hashnode&utm_medium=feed
A new Malware-as-a-Service platform evades 71 antivirus engines on first run and harvests 4,717 cookies, 55 passwords, and active session tokens from a single machine β in one pass.
The stolen VPN credentials it lifts are how ransomware gets in weeks later.
Full breakdown β https://relayshield.hashnode.dev/onyxc2-when-250-month-buys-everything-on-your-employees-devices?utm_source=hashnode&utm_medium=feed
β οΈ Rug pulls are now 54% of all crypto scams β 425,000+ detected
A token can have a rising chart, an active community, and polished marketing β and still be a rug pull waiting to execute. One hidden owner-side action and everything goes to zero.
How they work and how to screen counterparties before you send funds: https://relayshield.hashnode.dev/rug-pulls-are-now-54-of-all-crypto-threats-here-s-how-they-stay-hidden-until-it-s-too-late?utm_source=hashnode&utm_medium=feed
A token can have a rising chart, an active community, and polished marketing β and still be a rug pull waiting to execute. One hidden owner-side action and everything goes to zero.
How they work and how to screen counterparties before you send funds: https://relayshield.hashnode.dev/rug-pulls-are-now-54-of-all-crypto-threats-here-s-how-they-stay-hidden-until-it-s-too-late?utm_source=hashnode&utm_medium=feed
π¨ 24 billion credentials just surfaced in one of the largest leaks ever found.
Cybernews researchers found an exposed database this week: 8.3TB of infostealer logs, breach compilations, and credential dumps β sourced from over 30 criminal Telegram channels.
Plaintext passwords. Login URLs. Session cookies that bypass 2FA.
The database is offline. The Telegram channels are still posting new logs daily.
Full breakdown and what to do now β https://hashnode.com/@relayshieldsecurity
RelayShield monitors these channels in near real-time. If your credentials appear, you'll know within hours β not weeks.
Cybernews researchers found an exposed database this week: 8.3TB of infostealer logs, breach compilations, and credential dumps β sourced from over 30 criminal Telegram channels.
Plaintext passwords. Login URLs. Session cookies that bypass 2FA.
The database is offline. The Telegram channels are still posting new logs daily.
Full breakdown and what to do now β https://hashnode.com/@relayshieldsecurity
RelayShield monitors these channels in near real-time. If your credentials appear, you'll know within hours β not weeks.
Hashnode
RelayShieldAdmin (@relayshieldsecurity) | Hashnode
Crypto security signals for developers β wallet risk, token honeypots, SIM swap detection, and more in one REST API.
π¨ $2.9M stolen from Polymarket β the signals were in stealer logs before a single line of malicious code fired.
A compromised third-party vendor pushed malicious JavaScript to Polymarket's frontend. Users were silently robbed while everything looked normal.
We mapped the full signal chain attackers leave behind before supply chain attacks execute and which monitoring calls catch each one:
β Vendor credential exposure in infostealer archives
β Service account & CI/CD token theft (NHI exposure)
β Identity risk score elevation on the vendor domain
β ATT&CK TTP T1195 β Supply Chain Compromise
Full breakdown with API examples: [https://relayshield.hashnode.dev/how-relayshield-would-have-caught-the-polymarket-attack-before-it-cost-2-9-million?utm_source=hashnode&utm_medium=feed]
A compromised third-party vendor pushed malicious JavaScript to Polymarket's frontend. Users were silently robbed while everything looked normal.
We mapped the full signal chain attackers leave behind before supply chain attacks execute and which monitoring calls catch each one:
β Vendor credential exposure in infostealer archives
β Service account & CI/CD token theft (NHI exposure)
β Identity risk score elevation on the vendor domain
β ATT&CK TTP T1195 β Supply Chain Compromise
Full breakdown with API examples: [https://relayshield.hashnode.dev/how-relayshield-would-have-caught-the-polymarket-attack-before-it-cost-2-9-million?utm_source=hashnode&utm_medium=feed]
RelayShield is now live on AWS Marketplace.
Our Threat Intelligence & Identity Security API is now available as a self-serve SaaS listing for any AWS customer β same intelligence pipeline that powers our identity protection product, now accessible directly through AWS procurement.
What's inside:
β’ 2M+ indicator IOC corpus across 20+ feed sources
β’ 37+ monitored criminal Telegram channels, surfacing threats 24β72 hours before public disclosure
β’ STIX/TAXII 2.1 and MISP feed export for direct SIEM/SOAR integration
β’ Correlated signals across breach exposure, infostealer logs, SIM-swap, and session hijacking
If your org already buys through AWS, this is now the fastest way to plug identity-layer threat intelligence into your existing stack.
π https://aws.amazon.com/marketplace/pp/prodview-z3izf6val3jb2
Our Threat Intelligence & Identity Security API is now available as a self-serve SaaS listing for any AWS customer β same intelligence pipeline that powers our identity protection product, now accessible directly through AWS procurement.
What's inside:
β’ 2M+ indicator IOC corpus across 20+ feed sources
β’ 37+ monitored criminal Telegram channels, surfacing threats 24β72 hours before public disclosure
β’ STIX/TAXII 2.1 and MISP feed export for direct SIEM/SOAR integration
β’ Correlated signals across breach exposure, infostealer logs, SIM-swap, and session hijacking
If your org already buys through AWS, this is now the fastest way to plug identity-layer threat intelligence into your existing stack.
π https://aws.amazon.com/marketplace/pp/prodview-z3izf6val3jb2
Amazon
AWS Marketplace: RelayShield - Threat Intelligence & Identity Security API
RelayShield delivers threat intelligence and identity security via REST API - 2.0M+ IOC corpus, breach detection, SIM swap monitoring, infostealer exposure, ransomware victim tracking, and session hijack detection. Built for MSPs, MSSPs, and security-forwardβ¦
Crypto Shield Mobile is live on the Solana dApp Store.
Built on the same threat-intelligence pipeline as RelayShield's core platform β 2.1M+ indicator IOC corpus, 37+ monitored criminal Telegram channels β now packaged into a native wallet-security app.
What's new in this release:
β’ Mobile Wallet Adapter β connect your Solana wallet directly, no manual address entry (still fully read-only, no signing ever requested)
β’ NFT Security scanning β catches drainer contracts disguised as reward NFTs
β’ Address poisoning detection across transaction history
β’ Jupiter token verification status on Solana token scans
Read-only across Solana, EVM (including Base), TON, Bitcoin, and XRP. We never ask for your seed phrase β Crypto Shield can't move your funds.
π Available now on the Solana dApp Store: https://cryptoshieldmobile.relayshield.net
Built on the same threat-intelligence pipeline as RelayShield's core platform β 2.1M+ indicator IOC corpus, 37+ monitored criminal Telegram channels β now packaged into a native wallet-security app.
What's new in this release:
β’ Mobile Wallet Adapter β connect your Solana wallet directly, no manual address entry (still fully read-only, no signing ever requested)
β’ NFT Security scanning β catches drainer contracts disguised as reward NFTs
β’ Address poisoning detection across transaction history
β’ Jupiter token verification status on Solana token scans
Read-only across Solana, EVM (including Base), TON, Bitcoin, and XRP. We never ask for your seed phrase β Crypto Shield can't move your funds.
π Available now on the Solana dApp Store: https://cryptoshieldmobile.relayshield.net
cryptoshieldmobile.relayshield.net
Crypto Shield Mobile β Wallet security that watches your credentials, not just your chain
Read-only wallet security monitoring for Solana, EVM, TON, Bitcoin, and XRP. Never asks for your seed phrase or private keys.
Threat actors don't need to write new malware anymore. They just need $250/month.
Remus Stealer showed up in criminal marketplaces this spring β Google OAuth cookie restoration built in, meaning even after a victim changes their password, the attacker can regenerate access to their session. It's not novel code. It's Lumma's proven playbook, repackaged and resold as a subscription, three tiers, priced like SaaS.
We wrote up what it actually does, why "I changed my password" doesn't mean an incident is over, and what to actually check if you suspect compromise:
[https://www.linkedin.com/pulse/remus-stealer-new-250-a-month-infostealer-renting-out-your-e1goc/?trackingId=1qeb%2Bv0Gd2NBf6e%2B3%2B%2BZig%3D%3D]
RelayShield tracks 1,000+ malware families including Remus, in real time, from the same channels these logs get sold in.
Remus Stealer showed up in criminal marketplaces this spring β Google OAuth cookie restoration built in, meaning even after a victim changes their password, the attacker can regenerate access to their session. It's not novel code. It's Lumma's proven playbook, repackaged and resold as a subscription, three tiers, priced like SaaS.
We wrote up what it actually does, why "I changed my password" doesn't mean an incident is over, and what to actually check if you suspect compromise:
[https://www.linkedin.com/pulse/remus-stealer-new-250-a-month-infostealer-renting-out-your-e1goc/?trackingId=1qeb%2Bv0Gd2NBf6e%2B3%2B%2BZig%3D%3D]
RelayShield tracks 1,000+ malware families including Remus, in real time, from the same channels these logs get sold in.
Linkedin
Remus Stealer: The New $250-a-Month Infostealer Renting Out Your Google Session
The threat intelligence company Flashpoint first spotted it for sale in criminal marketplaces in March 2026. By the time most security teams heard the name, it was already a working product with a price list.
Shipped: an AI agent on AWS Bedrock AgentCore autonomously found and paid for one of our threat-intel APIs through Coinbase's x402 Bazaar: real USDC, real on-chain settlement, zero custom payment code.
tx: 0x1cb95ce37d54201b4def745269c42790fdb9bc7255f102aa648cf6f91fab0e3a (Base)
23 RelayShield endpoints are now discoverable and payable by any AI agent on AWS or x402-compatible frameworks with no integration needed on their end. This is what "agentic attack surface" defense looks like when the defender is also agent-native.
relayshield.net
tx: 0x1cb95ce37d54201b4def745269c42790fdb9bc7255f102aa648cf6f91fab0e3a (Base)
23 RelayShield endpoints are now discoverable and payable by any AI agent on AWS or x402-compatible frameworks with no integration needed on their end. This is what "agentic attack surface" defense looks like when the defender is also agent-native.
relayshield.net
π‘οΈ New: RelayShield security tools for smolagents agents, published on Hugging Face.
Four checks your agent can run before it trusts an MCP server or ingests content: mcp-registry-risk, prompt-injection-breach, tech-stack-cve, bulk-identity-risk. Pay-per-call, no subscription needed.
Full writeup: https://huggingface.co/blog/relayshieldadmin/smolagents-agent-security-tools
Four checks your agent can run before it trusts an MCP server or ingests content: mcp-registry-risk, prompt-injection-breach, tech-stack-cve, bulk-identity-risk. Pay-per-call, no subscription needed.
Full writeup: https://huggingface.co/blog/relayshieldadmin/smolagents-agent-security-tools
huggingface.co
Giving agent frameworks a threat-intel safety check: RelayShield's smolagents tools
A Blog post by relayshield on Hugging Face
π‘οΈ Update: RelayShield's agent security tools just went from 4 to 9 β direct response to community feedback on the original release.
New: oauth_watchlist, nhi_exposure, session_risk (grouped as one "agent authority" check), plus supply_chain and secret_scan. Every tool now returns a typed, explainable result instead of a plain string.
Full writeup: https://huggingface.co/blog/relayshieldadmin/smolagents-agent-security-tools-v2
New: oauth_watchlist, nhi_exposure, session_risk (grouped as one "agent authority" check), plus supply_chain and secret_scan. Every tool now returns a typed, explainable result instead of a plain string.
Full writeup: https://huggingface.co/blog/relayshieldadmin/smolagents-agent-security-tools-v2
huggingface.co
You Asked, We Shipped: 5 New Agent Security Tools, Structured Results, and Two Bugs We Found Along the Way
A Blog post by relayshield on Hugging Face
New research from the RelayShield team π
We checked 24 well-known DeFi, prediction market, and fintech companies for lookalike domains which are the typosquat variants attackers register before launching phishing campaigns.
The number: 341 registered, resolving lookalikes across those 24 brands.
The alarming part: only 1 is currently flagged by public blocklists as active phishing. The rest sit unclassified. Some are the brands' own defensive registrations, but plenty are dormant infrastructure that hasn't been activated yet. Blocklists only catch domains after they're already being used.
We didn't stop at "is it registered": For every hit we also check registration age and TLS certificate issuance timing, which is the closest thing to an early-warning signal before a domain shows up on anyone's blocklist.
Full research + methodology: [https://relayshield.hashnode.dev/341-lookalikes-1-alarm-domain-hygiene-research?utm_source=hashnode&utm_medium=feed]
Want to check your own domain? It's free, no signup: badge.relayshield.net
We checked 24 well-known DeFi, prediction market, and fintech companies for lookalike domains which are the typosquat variants attackers register before launching phishing campaigns.
The number: 341 registered, resolving lookalikes across those 24 brands.
The alarming part: only 1 is currently flagged by public blocklists as active phishing. The rest sit unclassified. Some are the brands' own defensive registrations, but plenty are dormant infrastructure that hasn't been activated yet. Blocklists only catch domains after they're already being used.
We didn't stop at "is it registered": For every hit we also check registration age and TLS certificate issuance timing, which is the closest thing to an early-warning signal before a domain shows up on anyone's blocklist.
Full research + methodology: [https://relayshield.hashnode.dev/341-lookalikes-1-alarm-domain-hygiene-research?utm_source=hashnode&utm_medium=feed]
Want to check your own domain? It's free, no signup: badge.relayshield.net
RelayShield Security Intelligence
Domain Lookalike Research: 24 Brands, 341 Typosquats Found
We checked 24 DeFi, prediction market, and fintech brands for lookalike domains. 341 found. Only 1 is blocklisted. Here's why that gap matters."
π‘οΈ New: a mandatory security gate for AI agents, not just an optional check.
Built on LangChain's wrap_tool_call middleware, it blocks an agent from connecting to an unfamiliar MCP server unless a security check clears first. Fails closed (never silently allows on error), 12 passing tests against the real framework.
Repo: https://github.com/nzdsf2-gif/relayshield-langchain-gate
Built on LangChain's wrap_tool_call middleware, it blocks an agent from connecting to an unfamiliar MCP server unless a security check clears first. Fails closed (never silently allows on error), 12 passing tests against the real framework.
Repo: https://github.com/nzdsf2-gif/relayshield-langchain-gate
GitHub
GitHub - nzdsf2-gif/relayshield-langchain-gate: Reference mandatory pre-execution gate (LangChain wrap_tool_call) for MCP serverβ¦
Reference mandatory pre-execution gate (LangChain wrap_tool_call) for MCP server connect/install risk checks - nzdsf2-gif/relayshield-langchain-gate