The 'Search-as-a-Service' Economy Built on Stolen Credentials
Underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar for access brokers and intrusion crews alike.

Key points
- Underground services now let buyers query aggregated stealer logs by domain or company name, paying only for matching results.
- The model collapses the work cycle for initial access brokers by removing the need to parse bulk log dumps.
- Stolen browser cookies returned alongside passwords let attackers bypass multi-factor authentication entirely.
- Attribution on service operators remains thin; the buyer pool includes both eCrime and nation-state-adjacent crews.
- Defenders need session revocation tied to password reset, not just credential rotation, and must treat cookie theft as a first-class detection problem.
Credential theft has scaled past the point where any single operator can meaningfully parse what they're sitting on. The market adapted.
A small but growing class of underground services now offers search-as-a-service over aggregated stealer logs and combolists. Buyers submit a domain or a target company; sellers return matching credentials, cookies, and host metadata pulled from terabyte-scale corpora harvested by infostealers including RedLine, Lumma, StealC, and Vidar.
The model isn't new in concept. Russian Market and 2easy have indexed stealer logs for years, and Telegram channels have long offered keyword lookups for a fee. What's shifting is the productization: several actors are now running tiered subscription plans and web front-ends that look closer to a SaaS dashboard than a forum thread.
Does this actually change anything for attackers?
It does, in two concrete ways.
First, it collapses the work cycle for initial access brokers. Instead of buying a bulk log dump and hoping for a useful hit against a named target, a buyer can query for @victimcorp.com and pay only for what comes back. That's a meaningful efficiency gain for ransomware affiliates and the access-broker tier that feeds them. Activity overlapping with clusters tracked as Scattered Spider (CrowdStrike's naming) has historically relied on exactly this kind of credential sourcing for initial footholds, a pattern we examined on 10 June when infostealers displaced exploit-based access across the ransomware chain.
Second, it changes the defender calculus on session hijacking. Stealer logs typically include browser cookies alongside passwords, and a targeted lookup means an attacker can request active session material for a specific SaaS tenant. MFA doesn't help if the attacker imports a live okta.com or microsoftonline.com cookie into an anti-detect browser. CISA flagged the pattern in its 2024 advisory on identity-based intrusions.
Should you worry about nation-state buyers?
Attribution on the operators behind these search services remains thin. Most front-ends are run by financially motivated actors with no clear nation-state nexus, though the buyer pool is mixed. With medium confidence, the same infrastructure has been used by intrusion crews whose downstream activity overlaps with both eCrime and DPRK-linked clusters. Kimsuky operators, in particular, have historically purchased stealer output rather than running their own collection at scale.
What can defenders actually do?
The options are narrow but concrete. Monitor for credential exposure against your own domains using services that ingest stealer logs, including HaveIBeenPwned's Pwned Passwords and enterprise equivalents. Force session revocation on password reset, not just credential rotation. Treat cookie theft as a first-class detection problem, with conditional access policies that bind sessions to device posture.
The underground market has figured out how to monetize the long tail of stolen data. Defenders haven't caught up to the indexing yet, and that gap is the whole story.



