Blogs>Infostealers Are the New Front Door: A Cyber Drill Scenario for Credential-Based Attacks

Infostealers Are the New Front Door: A Cyber Drill Scenario for Credential-Based Attacks

Simulations Labs
📅September 20, 2026
Infostealers Are the New Front Door: A Cyber Drill Scenario for Credential-Based Attacks

Infostealers Are the New Front Door: A Cyber Drill Scenario for Credential-Based Attacks

Most security teams still picture a breach beginning with a clever exploit. This month's headlines tell a different story. Alongside a record-breaking Patch Tuesday, the incidents that kept surfacing in September 2026 involved stolen logins, hijacked sessions, and edge VPNs accessed with credentials that looked entirely legitimate. The attacker did not break in. They logged in.

That shift has a clear engine behind it: infostealer malware. And because it changes where an attack begins, it also changes what your team needs to practice.

nested Image Search Query: "SOC analyst monitor security alert session anomaly" Alt Text: Security operations center screen showing a stealer-log alert and session hijacking timeline

Why Infostealers Have Become the Entry Point of Choice

Infostealers are lightweight, commercially available malware families, such as Lumma, Vidar, and Stealc, that quietly harvest saved browser passwords, session cookies, VPN credentials, and authentication tokens from an infected device. That data is then sold to initial access brokers and, ultimately, to ransomware operators. Infections typically arrive through cracked software, malicious ads, or poisoned downloads, and frequently land on unmanaged personal devices where corporate and personal logins sit side by side.

The scale is significant. Flashpoint's 2025 Global Threat Intelligence Index estimated that infostealers harvested around 1.8 billion credentials in the first half of 2025 alone — an 800% increase over the prior period. Flashpoint's own analysis, drawing on the 2025 Verizon Data Breach Investigations Report, found that 54% of organizations hit by ransomware also had domain credentials appear in stealer-log marketplaces before the attack. Cisco Talos's Q1 2026 Incident Response Trends report documented phishing and credential-based access reemerging as the leading initial access vector, overtaking exploit-driven intrusions that quarter.

Speed is what should concern defenders most. CYFIRMA's threat intelligence research indicates that ransomware groups are now obtaining validated access and deploying payloads within 48 hours of credentials appearing on underground markets. That leaves very little room for a response plan that exists only on paper.

Why MFA Alone Will Not Save You

Stolen session cookies allow an attacker to reuse a session that is already authenticated. From the server's perspective, there is no new login to challenge, so multi-factor authentication never triggers. This is why the correct response to a stealer infection is not simply a password reset. Teams must revoke active sessions, rotate tokens and secrets, and review identity and cloud logs for access from unfamiliar devices or locations.

Understanding this in theory is straightforward. Executing it under pressure, at 2 a.m., with incomplete information, is a different skill entirely. That is precisely what a drill is for.

The following four-phase scenario can be adapted for a tabletop exercise or, ideally, a hands-on cyber drill where participants work with realistic logs and systems. Each phase includes an inject, a team objective, and a key question for discussion.

Four-phase timeline diagram of an infostealer-to-ransomware attack chain

Phase 1: The Infection Nobody Noticed

Inject: A finance employee's personal laptop, occasionally used for work email, is infected after installing a free PDF editor. The stealer exfiltrates saved credentials and active session cookies for the corporate SaaS suite and VPN.

Objective: Identify, from endpoint telemetry and threat intelligence, that credentials have been exposed and determine which accounts and sessions are affected.

Key question: Do you monitor stealer-log feeds for your own domain, and who owns that alert?

Phase 2: The Quiet Login

Inject: Thirty-six hours later, the employee's session is replayed from a new geography. No MFA prompt is triggered. The attacker reads email threads and extracts a list of vendor contacts.

Objective: Detect anomalous session activity and revoke sessions, not merely reset the password.

Key question: How quickly can you force a global sign-out for a single identity?

Phase 3: Through the Edge

Inject: Using the harvested VPN credentials, the attacker authenticates to an edge VPN appliance and begins internal reconnaissance, searching for privileged accounts.

Objective: Contain the foothold, isolate affected segments, and trace lateral movement.

Key question: Would a single stolen credential give an attacker this much reach in your environment?

Phase 4: The Extortion Clock

Inject: A ransom note appears, accompanied by a sample of exfiltrated data and a 72-hour deadline.

Objective: Coordinate technical containment with legal, communications, and leadership, and make informed decisions on disclosure and recovery.

Key question: Has your incident response plan ever been tested against an attacker who held valid credentials from day one?

What to Measure

A drill is only as valuable as what you learn from it. Track time to detect the credential exposure, time to revoke sessions, whether the team correctly distinguished session hijacking from a simple password compromise, and how smoothly handoffs occurred between the SOC, IT, and leadership. Repeat the scenario a quarter later and compare results. Measurable improvement is evidence of readiness you can present to your board.

Run This Drill on Simulations Labs

Simulations Labs is an all-in-one platform for hosting hands-on cybersecurity simulations, from CTF competitions to full-scale cyber drills and cyber ranges, without building the infrastructure yourself. Simulations Labs' Cyber Range lets you turn this exact infostealer scenario into a scored, live-fire exercise, drawing on an extensive scenario library and using built-in analytics to see exactly where your team performs with confidence and where it hesitates. For teams building this into a recurring program rather than a one-time drill, security team upskilling tracks give you a structured way to repeat and measure this scenario quarter over quarter.

Attackers rehearse their playbook every day. Your team should be rehearsing theirs.

Ready to run this scenario as a scored, live-fire drill? Get started for free on Simulations Labs (no credit card required), or view a demo to see it in action.

FAQ

Why don't infostealer-based attacks trigger MFA alerts? Because they steal an already-authenticated session cookie rather than a username and password. The server sees what looks like a continuation of a valid session, not a new login attempt, so there's nothing for MFA to challenge. This is why session revocation, not just a password reset, is the correct first response.

How fast do attackers typically move after obtaining stolen credentials? CYFIRMA's threat intelligence research found ransomware groups obtaining validated access and deploying payloads within 48 hours of credentials appearing on underground markets — a narrow window that makes a rehearsed, fast response plan essential rather than optional.

Is a tabletop exercise enough, or does this need a hands-on drill? A tabletop exercise is a reasonable starting point for walking through decision points, but it doesn't test whether a team can actually execute technical steps like forcing a global session revocation under time pressure. A hands-on drill with realistic logs and systems tests the actual execution, not just the discussion.

What's the difference between a password reset and a session revocation? A password reset stops an attacker from logging in again in the future, but it does nothing to a session that's already active — a stolen session cookie remains valid until it's explicitly revoked. Full incident response requires revoking active sessions and rotating tokens, not just changing the password.

How often should an organization run a drill like this? Repeating the scenario on a quarterly cadence, and comparing time-to-detect and time-to-revoke metrics between runs, gives you measurable evidence of improvement — which is also useful evidence of security posture to present to a board or leadership team.