Sources: api-pro.ransomware.live + hudsonrock.com · Period: Q2 2026 · 10 victims analysed
Key Findings
10 UK CNI victims recorded
In Q2 2026, 10 UK Critical National Infrastructure organisations carried confirmed infostealer telemetry, spanning 13 distinct stealer families across 5 CNI sectors, averaging 3 per month across the quarter.
Unknown Stealer leads detections
Unknown Stealer was the most prevalent stealer family, generating 278 credential-set detections, representing 20.5% of all detections this period.
20.0% of victims have a named family
2 of 10 UK CNI victims, or 20.0%, had a specific stealer family attributed by Ransomware.Live. The remainder are confirmed infostealer exposure reported as Unknown Stealer without a published family breakdown.
Manufacturing hardest-hit sector
Manufacturing was the most targeted CNI sector, accounting for 40.0% of all victims. APT73 was the most active threat actor, linked to 1 victim.
Quarter Snapshot
10 Total Victims
This quarter | 1.4K Detections
Credential sets | Unknown Stealer Top Stealer
20.5% of detections |
5 CNI Sectors
Sectors affected | 13 Stealer Families
Active this period | APT73 Most Active Group
1 victim |
BACKGROUND
WHAT IS AN INFOSTEALER?
An infostealer is a type of malware built to quietly harvest sensitive data from an infected device rather than encrypt or destroy anything. Once installed - typically via cracked software, fake installers, malicious adverts, or phishing attachments - it scrapes browser-saved passwords, active session cookies, autofill data, cryptocurrency wallets, and VPN or RDP configuration files, then sends everything back to the attacker in a single package known as a "log".
These logs circulate rapidly through criminal forums and private channels, often reaching ransomware affiliates within days of infection. A log containing valid VPN or remote-desktop credentials for a target organisation can provide ready-made network access, skipping the phishing and exploitation stages entirely. BCON Collective monitors these channels continuously - the credential theft frequently happens weeks or months before the ransomware payload is deployed, making infostealer exposure one of the most actionable early warning signals available.
Well-known families referenced throughout this report - RedLine, Lumma, Raccoon, StealC, and Vidar among them - are typically operated as Malware-as-a-Service, lowering the barrier to entry for criminal actors and accelerating deployment. BCON Collective tracks active stealer families and their infrastructure as part of our managed threat intelligence service.
WHAT'S BEING COUNTED:
Every figure in this report reflects only victims with confirmed, non-zero infostealer exposure. Records with no infostealer data - or where every field is empty/zero - are excluded entirely. Confirmed exposure without a named stealer family is reported as "Unknown Stealer" rather than dropped.
QUATER-ON-QUATER
LONGER-TERM TRAJECTORY
This view complements the current-quarter analysis by showing how infostealer-linked victim volume and detection counts have moved across recent quarters - separating short-term noise from the broader directional trend.

Across the 6-quarter window ending Q2 2026, infostealer-linked victim postings show a broadly stable trajectory, going from 10 in Q1 2025 to 10 currently - sitting +67% above the 6-victim rolling baseline. In the most recent quarter, postings increased by +233% quarter-on-quarter, while detections rose +6665% to 1.4K. The peak in this window was 10 victims in Q1 2025.
EMERGING THREATS
New and Rising Stealer Families
Families that either appeared for the first time this quarter, grew sharply month-on-month, or dropped off sharply after previously being active - tracking all three flags emerging threats early and shows which families may be fading out of use. "Unknown Stealer" is excluded here, since it has no confirmed family attribution.
Between April and June, infostealer-linked victim postings decreased from 3 to 1. The number of active stealer families narrowed from 13 to 1.
Month-over-Month
- What changed within the Quater


SECTOR ANALYSIS
CNI Sector Breakdown
Ranked view of which Critical National Infrastructure sectors were hit hardest by infostealer-linked ransomware in the selected period.

Manufacturing was the hardest-hit CNI sector in this period, accounting for 40% of all UK CNI victims. Victims spanned 5 of the NCSC's Critical National Infrastructure sectors; the top three sectors collectively represented 80% of all activity.
MARKET STRUCTURE
Stealer Family Concentration
How much of total detection volume is held by a small number of dominant families. A higher concentration means defenders can focus detection engineering on fewer, better-understood threats.

MALWARE ANALYSIS
Top Infostealer Families
Among UK CNI victims, chart reflects which stealer families were confirmed for the period and filters selected above.

UK LANDSCAPE
UK Ransomeware & Infostealer Activity
Monthly UK victim trends and the sectors most frequently targeted, based on victims with confirmed infostealer telemetry in the selected period.


THREAT INTELLIGENCE
Top Threat Actors
Groups ranked by number of victims with confirmed infostealer data attached to their incident record.

GLOBAL BENCHMARK
RANSOMWARE GROUPS BY INFOSTEALER ADOPTION
Which ransomware groups rely most heavily on infostealer credentials as part of their playbook - measured as the share of a group's entire global victim base (every country, every sector) that carries confirmed infostealer data. This is deliberately not limited to UK CNI, since a meaningful adoption rate needs a much larger sample than the UK-only figures elsewhere in this report can provide.

CREDENTIAL EXPOSURE
Scale of Credential Damage
Credentials exposed across victims with infostealer data, broken down by employee, consumer, and third-party accounts.


VICTIM DETAIL
UK CNI VICTIM RECORDS
Individual incidents affecting UK organisations within - or adjacent to - the NCSC's Critical National Infrastructure sectors: telecoms, healthcare, financial services, transport, energy, government, manufacturing, agriculture & food, water, defence, chemicals, and emergency services. Adjust the filters above to narrow further.
This report - and every figure throughout it - counts only victims with confirmed, non-zero infostealer exposure. Records with no infostealer data, or where every field (employee/consumer/third-party credentials and per-family detections) is empty or zero, are excluded entirely rather than treated as a data point. Where exposure is confirmed but Ransomware.Live hasn't published which stealer family was responsible, that victim is labelled "Unknown Stealer" rather than dropped.

10 of 10 UK CNI victims - 2 include a published per-family detection breakdown (Detected); the remaining 8 have confirmed credential exposure but no named stealer family published, shown here as "Unknown Stealer" (Partial). Records with no infostealer signal at all, or with every field empty/zero, are excluded entirely.
CREDENTIAL INTELLIGENCE
TOP STOLEN CREDENTIALS
Cross-references domains extracted from the UK CNI victims above against Bridewell's infostealer intelligence sources - reporting only the third-party services most often found alongside stolen corporate access in the same logs. Bridewell's credential monitoring capability surfaces this exposure continuously, not only at report time.

DEFENSIVE GUIDANCE
PREVENT · DETECT · RESPOND
Treat infostealer evidence as an independent threat, not just a precursor to ransomware. Credential theft often happens weeks or months before the destructive event - organised here across the full lifecycle: stopping infections before they happen, catching the ones that get through, and reacting fast when stolen credentials are confirmed.
PREVENT • Harden Endpoint & Browser Credential Storage: Disable browser-saved passwords for privileged accounts, enforce application allowlisting, and block script and executable launches from user-writable folders such as Downloads and Temp - the most common infostealer execution paths. Bridewell's endpoint hardening assessments identify these exposure points across your environment. • Target Awareness Training at Infostealer Delivery Vectors: Most infostealer infections originate from cracked software, fake installers, or malvertising rather than traditional phishing. Awareness programmes should explicitly cover these vectors, not just email-based attacks. | DETECT • Tune EDR for Stealer-Specific Behaviours: Configure EDR detections for LSASS memory access, bulk browser credential-store reads, and clipboard hijacking rather than relying on signature-based antivirus, which most current stealer families evade. Bridewell's managed detection and response (MDR) service includes pre-tuned detection rules for infostealer-specific behaviours across your endpoint estate. • Monitor for Anomalous Authentication: Watch for impossible-travel logins, new-device authentication paired with an existing session token, and access patterns inconsistent with a user's normal behaviour - all indicators of stolen-credential reuse. Bridewell's SOC monitors these signals around the clock, correlating authentication telemetry with our threat intelligence feeds to distinguish credential reuse from legitimate access. | RESPOND • Run an Infostealer-Specific IR Playbook: Treat a confirmed infostealer match as an active incident, not routine hygiene: scope which systems and accounts were exposed, check for lateral movement, and assume the credentials may already be in active use. Bridewell's incident response team has direct experience handling infostealer-linked intrusions and can support triage, containment, and recovery. • Coordinate Third-Party Notification: Third-party credentials make up a large share of total exposure. When a supplier's credentials appear in a log tied to your organisation, notify them promptly and confirm their own remediation before restoring access. Bridewell's CTI team can monitor third-party exposure continuously - alerting you when supplier credentials surface in infostealer logs before they're exploited against your supply chain. |
|---|