The Rise of Service-Centric Credential Compilations

How Cybercriminals Are Repackaging Infostealer Data

Over the last year, the underground economy has undergone a significant transformation. Cybercriminals are no longer focused on distributing massive collections of raw infostealer logs, they are increasingly investing time in organizing and enriching stolen information into service-specific compilations. These datasets are no longer random collections of credentials extracted from infected endpoints. Instead, they are carefully curated packages containing only the information associated with a particular online service such as ChatGPT, Netflix, Microsoft 365, Google Workspace or social media platforms. This evolution reflects the growing professionalization of the cybercriminal ecosystem and the increasing demand for ready-to-use access rather than raw data.

Traditional infostealer logs often contain millions of records originating from thousands of infected devices. While valuable, these datasets require considerable effort to process, filter and validate before they can be monetized. Today, a new criminal business model has emerged in which specialized actors process those logs, identify the most valuable services, verify the freshness of the information and build premium compilations focused on a single platform. Buyers no longer need to search through enormous datasets to find valid credentials. Instead, they purchase curated collections containing everything required to target one specific service, significantly reducing operational effort while increasing the probability of successful account compromise.

One of the key drivers behind this evolution is the growing role played by Initial Access Brokers (IABs). Rather than simply selling access obtained from compromised machines, many IABs now enrich stolen information before offering it to other criminals. Fresh credentials extracted from infostealer infections are combined with browser artifacts, session cookies and authentication tokens before being repackaged into service-oriented datasets. This substantially increases the commercial value of the stolen information because customers are purchasing immediate opportunities instead of incomplete raw data. In practice, this represents a shift from selling infections to selling outcomes.

Modern compilations rarely contain only usernames and passwords. In many cases they include browser cookies, persistent session cookies, refresh tokens, JWTs, CSRF tokens, device identifiers and other authentication artifacts recovered directly from the victim’s browser. These artifacts represent the authenticated state of a user’s session and, depending on the authentication model implemented by the service, may allow attackers to reuse an already authenticated session while those tokens remain valid. This means that, in certain scenarios, attackers may not need to know the user’s password or repeatedly complete multi-factor authentication challenges. For cybercriminals, this dramatically increases the value of each compromised account because they are purchasing not only an identity but also an active digital session.

This trend becomes particularly concerning when applied to modern AI platforms such as ChatGPT, Claude, Gemini and other enterprise AI assistants. A compromised ChatGPT account is far more valuable than access to a traditional web service. These platforms increasingly contain sensitive corporate knowledge, proprietary source code, strategic business plans, financial analysis, legal documents, internal procedures and confidential conversations that users routinely share with AI assistants. In enterprise environments, employees frequently use these platforms to summarize meetings, analyze customer data, debug proprietary software, generate technical documentation or discuss confidential projects. As organizations continue integrating AI into their daily workflows, these conversations effectively become a new repository of corporate intellectual property.

The risks extend well beyond traditional account takeover. Access to AI services can enable intelligence gathering against an organization, accelerate social engineering campaigns by leveraging internal communications, reveal software development practices, expose confidential customer information or disclose strategic initiatives that were never intended to leave the organization. For threat actors conducting espionage, ransomware operations or business email compromise campaigns, access to enterprise AI conversations may provide context that significantly improves the effectiveness of subsequent attacks.

The underground market has clearly recognized this opportunity. Rather than trading generic credential dumps, cybercriminals are increasingly commercializing complete digital identities, packages that combine credentials, browser cookies, authentication tokens and contextual information for a specific online service. As AI platforms continue becoming central repositories for corporate knowledge, these service-centric compilations will likely become even more valuable. Defenders must therefore expand their security strategies beyond password protection alone, treating browser cookies, authentication tokens and active sessions as critical assets that require continuous monitoring, rapid revocation and proactive detection across the cybercriminal ecosystem.

Figure 1. Example of a service-centric ChatGPT package combining identity information (anonymized), browser cookies artifacts extracted from an active browser session.

The example above illustrates how modern packages contain considerably more than a username and password. Criminal buyers value these complete packages because they maximize the likelihood that at least part of the stolen session remains usable.

Figure 2. Example of a Netflix compilation including account metadata alongside authentication tokens associated with the victim’s session.

For defenders, this trend reinforces the need to treat browser cookies and authentication tokens with the same level of protection as passwords. Credential rotation alone may not immediately invalidate every active session if valid session artifacts remain in circulation.

Effective response should therefore include:

  • rapid session invalidation and token revocation;
  • continuous monitoring of exposed identities;
  • adaptive MFA and device-risk analysis;
  • visibility into underground marketplaces where service-centric compilations are traded.

Organizations should also assume that fresh data moves rapidly across the cybercriminal supply chain, often reaching multiple resellers only hours after the original infection.

The underground economy is becoming increasingly specialized, automated and commercially efficient. Service-specific compilations show how cybercriminals are optimizing every stage of the monetization process by transforming raw infostealer output into immediately actionable access packages.

As long as fresh browser sessions, cookies and authentication tokens continue to command a premium price, defenders must broaden their security strategy beyond passwords and monitor the full lifecycle of digital identities exposed outside the enterprise perimeter.