UK CNI Infostealer Threat Insights banner image
Blog
BCON COLLECTIVE

UK CNI Infostealer Threat Insights

By Daniel Whitcombe 10 August 2026 13 min read
Live analysis of credential theft malware targeting UK Critical National Infrastructure - pulled directly from the Ransomware.Live PRO API and enriched with infostealer intelligence by BCON Collective for the period selected above.

Sources: api-pro.ransomware.live + hudsonrock.com · Period: Q2 2026 · 10 victims analysed

Key Findings

01

10 UK CNI victims recorded

In Q2 2026, 10 UK Critical National Infrastructure organisations carried confirmed infostealer telemetry, spanning 13 distinct stealer families across 5 CNI sectors, averaging 3 per month across the quarter.

02

Unknown Stealer leads detections

Unknown Stealer was the most prevalent stealer family, generating 278 credential-set detections, representing 20.5% of all detections this period.

03

20.0% of victims have a named family

2 of 10 UK CNI victims, or 20.0%, had a specific stealer family attributed by Ransomware.Live. The remainder are confirmed infostealer exposure reported as Unknown Stealer without a published family breakdown.

04

Manufacturing hardest-hit sector

Manufacturing was the most targeted CNI sector, accounting for 40.0% of all victims. APT73 was the most active threat actor, linked to 1 victim.


Quarter Snapshot

10
Total Victims

This quarter

1.4K
Detections

Credential sets

Unknown Stealer
Top Stealer

20.5% of detections

5
CNI Sectors

Sectors affected

13
Stealer Families

Active this period

APT73
Most Active Group

1 victim

 

BACKGROUND

WHAT IS AN INFOSTEALER?

An infostealer is a type of malware built to quietly harvest sensitive data from an infected device rather than encrypt or destroy anything. Once installed - typically via cracked software, fake installers, malicious adverts, or phishing attachments - it scrapes browser-saved passwords, active session cookies, autofill data, cryptocurrency wallets, and VPN or RDP configuration files, then sends everything back to the attacker in a single package known as a "log".

These logs circulate rapidly through criminal forums and private channels, often reaching ransomware affiliates within days of infection. A log containing valid VPN or remote-desktop credentials for a target organisation can provide ready-made network access, skipping the phishing and exploitation stages entirely. BCON Collective monitors these channels continuously - the credential theft frequently happens weeks or months before the ransomware payload is deployed, making infostealer exposure one of the most actionable early warning signals available.

Well-known families referenced throughout this report - RedLine, Lumma, Raccoon, StealC, and Vidar among them - are typically operated as Malware-as-a-Service, lowering the barrier to entry for criminal actors and accelerating deployment. BCON Collective tracks active stealer families and their infrastructure as part of our managed threat intelligence service.

WHAT'S BEING COUNTED:

Every figure in this report reflects only victims with confirmed, non-zero infostealer exposure. Records with no infostealer data - or where every field is empty/zero - are excluded entirely. Confirmed exposure without a named stealer family is reported as "Unknown Stealer" rather than dropped.


QUATER-ON-QUATER

LONGER-TERM TRAJECTORY

This view complements the current-quarter analysis by showing how infostealer-linked victim volume and detection counts have moved across recent quarters - separating short-term noise from the broader directional trend.

Figure 1 - QTR Trend

Across the 6-quarter window ending Q2 2026, infostealer-linked victim postings show a broadly stable trajectory, going from 10 in Q1 2025 to 10 currently - sitting +67% above the 6-victim rolling baseline. In the most recent quarter, postings increased by +233% quarter-on-quarter, while detections rose +6665% to 1.4K. The peak in this window was 10 victims in Q1 2025.


EMERGING THREATS

New and Rising Stealer Families

Families that either appeared for the first time this quarter, grew sharply month-on-month, or dropped off sharply after previously being active - tracking all three flags emerging threats early and shows which families may be fading out of use. "Unknown Stealer" is excluded here, since it has no confirmed family attribution.

Between April and June, infostealer-linked victim postings decreased from 3 to 1. The number of active stealer families narrowed from 13 to 1.

Month-over-Month

  • What changed within the Quater

Figure 2 - monthly breakdown Q2 2026

Figure 3 - new and rising families


SECTOR ANALYSIS

CNI Sector Breakdown

Ranked view of which Critical National Infrastructure sectors were hit hardest by infostealer-linked ransomware in the selected period.

Figure 4 - UK CNI VICTIMS BY SECTOR

Manufacturing was the hardest-hit CNI sector in this period, accounting for 40% of all UK CNI victims. Victims spanned 5 of the NCSC's Critical National Infrastructure sectors; the top three sectors collectively represented 80% of all activity.


MARKET STRUCTURE

Stealer Family Concentration

How much of total detection volume is held by a small number of dominant families. A higher concentration means defenders can focus detection engineering on fewer, better-understood threats.

Figure 5 - Concentration of detections


MALWARE ANALYSIS

Top Infostealer Families

Among UK CNI victims, chart reflects which stealer families were confirmed for the period and filters selected above.

Figure 6 - detection volume


UK LANDSCAPE

UK Ransomeware & Infostealer Activity

Monthly UK victim trends and the sectors most frequently targeted, based on victims with confirmed infostealer telemetry in the selected period.

Figure 7 - Monthly UK Victim Count

Figure 8 - Sector Targeted


THREAT INTELLIGENCE

Top Threat Actors

Groups ranked by number of victims with confirmed infostealer data attached to their incident record.

Figure 9 - Groups by Victim Count


GLOBAL BENCHMARK

RANSOMWARE GROUPS BY INFOSTEALER ADOPTION

Which ransomware groups rely most heavily on infostealer credentials as part of their playbook - measured as the share of a group's entire global victim base (every country, every sector) that carries confirmed infostealer data. This is deliberately not limited to UK CNI, since a meaningful adoption rate needs a much larger sample than the UK-only figures elsewhere in this report can provide.

Figure 10 - Top Ransomeware Groups


CREDENTIAL EXPOSURE

Scale of Credential Damage

Credentials exposed across victims with infostealer data, broken down by employee, consumer, and third-party accounts.

Figure 12 - Credential ExposureFigure 11 - Credential Type Distribution


VICTIM DETAIL

UK CNI VICTIM RECORDS

Individual incidents affecting UK organisations within - or adjacent to - the NCSC's Critical National Infrastructure sectors: telecoms, healthcare, financial services, transport, energy, government, manufacturing, agriculture & food, water, defence, chemicals, and emergency services. Adjust the filters above to narrow further.

This report - and every figure throughout it - counts only victims with confirmed, non-zero infostealer exposure. Records with no infostealer data, or where every field (employee/consumer/third-party credentials and per-family detections) is empty or zero, are excluded entirely rather than treated as a data point. Where exposure is confirmed but Ransomware.Live hasn't published which stealer family was responsible, that victim is labelled "Unknown Stealer" rather than dropped.

10 of 10 UK CNI victims - 2 include a published per-family detection breakdown (Detected); the remaining 8 have confirmed credential exposure but no named stealer family published, shown here as "Unknown Stealer" (Partial). Records with no infostealer signal at all, or with every field empty/zero, are excluded entirely.


CREDENTIAL INTELLIGENCE

TOP STOLEN CREDENTIALS

Cross-references domains extracted from the UK CNI victims above against Bridewell's infostealer intelligence sources - reporting only the third-party services most often found alongside stolen corporate access in the same logs. Bridewell's credential monitoring capability surfaces this exposure continuously, not only at report time.

Top compromised Third Party Services


DEFENSIVE GUIDANCE

PREVENT · DETECT · RESPOND

Treat infostealer evidence as an independent threat, not just a precursor to ransomware. Credential theft often happens weeks or months before the destructive event - organised here across the full lifecycle: stopping infections before they happen, catching the ones that get through, and reacting fast when stolen credentials are confirmed.

PREVENT
Enforce Phishing-Resistant MFA: Replace TOTP/SMS codes with FIDO2/WebAuthn hardware keys on all privileged and remote-access accounts. Modern infostealer families specifically target session cookies and authenticator codes stored on disk - hardware-bound keys eliminate this attack path entirely. Bridewell can assess your current MFA posture and identify gaps across your estate.

Harden Endpoint & Browser Credential Storage: Disable browser-saved passwords for privileged accounts, enforce application allowlisting, and block script and executable launches from user-writable folders such as Downloads and Temp - the most common infostealer execution paths. Bridewell's endpoint hardening assessments identify these exposure points across your environment.

Target Awareness Training at Infostealer Delivery Vectors: Most infostealer infections originate from cracked software, fake installers, or malvertising rather than traditional phishing. Awareness programmes should explicitly cover these vectors, not just email-based attacks.

DETECT
Maintain Continuous Infostealer Log Monitoring: Bridewell's credential monitoring service continuously tracks infostealer logs and dark web sources for exposure of your organisation's domains and credentials - surfacing alerts before ransomware actors can exploit what's been stolen. The window between credential theft and active exploitation is typically days to weeks, making continuous monitoring - not periodic checks - the only effective posture.

Tune EDR for Stealer-Specific Behaviours: Configure EDR detections for LSASS memory access, bulk browser credential-store reads, and clipboard hijacking rather than relying on signature-based antivirus, which most current stealer families evade. Bridewell's managed detection and response (MDR) service includes pre-tuned detection rules for infostealer-specific behaviours across your endpoint estate.

Monitor for Anomalous Authentication: Watch for impossible-travel logins, new-device authentication paired with an existing session token, and access patterns inconsistent with a user's normal behaviour - all indicators of stolen-credential reuse. Bridewell's SOC monitors these signals around the clock, correlating authentication telemetry with our threat intelligence feeds to distinguish credential reuse from legitimate access.

RESPOND
Rotate Credentials and Invalidate Sessions Immediately: On any confirmed infostealer log match, rotate the affected credentials and invalidate all active sessions the same day - don't wait for a scheduled password-rotation cycle. Stolen session cookies remain usable until explicitly revoked.

Run an Infostealer-Specific IR Playbook: Treat a confirmed infostealer match as an active incident, not routine hygiene: scope which systems and accounts were exposed, check for lateral movement, and assume the credentials may already be in active use. Bridewell's incident response team has direct experience handling infostealer-linked intrusions and can support triage, containment, and recovery.

Coordinate Third-Party Notification: Third-party credentials make up a large share of total exposure. When a supplier's credentials appear in a log tied to your organisation, notify them promptly and confirm their own remediation before restoring access. Bridewell's CTI team can monitor third-party exposure continuously - alerting you when supplier credentials surface in infostealer logs before they're exploited against your supply chain.

 

Discover how BCON Collective helps organisations identify, monitor and respond to emerging cyber threats.
CTI Analyst

Daniel Whitcombe

CTI Analyst

Daniel Whitcombe is a Threat Intelligence Analyst working within CTI at Bridewell and has prev... Daniel Whitcombe is a Threat Intelligence Analyst working within CTI at Bridewell and has previous experience within the Financial Sector.
Read