The 'Search-as-a-Service' Economy Built on Stolen Credentials
Underground brokers now sell targeted lookups against stolen credential corpora, lowering the bar for access brokers and intrusion crews alike.

Credential theft has scaled past the point where any single operator can meaningfully parse what they're sitting on. The market adapted.
A small but growing class of underground services now offers what amounts to search-as-a-service over aggregated stealer logs and combolists. Buyers submit a domain, an email pattern, or a target company. Sellers return matching credentials, cookies, and host metadata pulled from terabyte-scale corpora harvested by infostealers like RedLine, Lumma, StealC, and Vidar.
The model is not new in concept. Russian Market and 2easy have indexed stealer logs for years, and Telegram channels have long offered keyword lookups for a fee. What's shifting is the productization. Several actors are running tiered subscription plans, API endpoints, and even web front-ends that look closer to a SaaS dashboard than a forum thread.
This matters for two reasons.
First, it collapses the work cycle for initial access brokers. Instead of buying a 50GB log dump and hoping for a useful hit against a Fortune 500 target, a buyer can query for @victimcorp.com and pay only for what comes back. That's a meaningful efficiency gain for ransomware affiliates and the access-broker tier that feeds them. Activity overlapping with clusters tracked as Scattered Spider (CrowdStrike's naming) and the broader UNC3944 grouping (Mandiant) has historically relied on exactly this kind of credential sourcing for initial footholds.
Second, it changes the defender calculus on session hijacking. Stealer logs typically include browser cookies alongside passwords, and a targeted lookup means an attacker can request active session material for a specific SaaS tenant. MFA doesn't help if the attacker imports a live okta.com or microsoftonline.com cookie into an anti-detect browser. CISA flagged the pattern in its 2024 advisory on identity-based intrusions, and the underlying technique maps to MITRE T1539.
Attribution on the operators behind these search services remains thin. Most front-ends are run by financially motivated actors with no clear nation-state nexus, though the buyer pool is mixed. With medium confidence, the same infrastructure has been used by intrusion crews whose downstream activity overlaps with both eCrime and DPRK-linked clusters — Kimsuky operators, in particular, have historically purchased stealer output rather than running their own collection at scale.
What defenders can actually do is narrow.
Monitor for credential exposure against your own domains using services that ingest stealer logs (HaveIBeenPwned's Pwned Passwords and enterprise equivalents). Force session revocation on password reset, not just credential rotation. Treat cookie theft as a first-class detection problem, with conditional access policies that bind sessions to device posture.
The market has figured out how to monetize the long tail of stolen data. The defensive side has not yet caught up to the indexing.



