argus scan --domain
How many of your company's machines have already been infected?
Infostealers harvest credentials from real machines — employees, customers and vendors. Look up your company domain and see what is already circulating.
The dataset that may have already found your company
data as of 08/05/2026 · Argus intelligence baseThe same data infrastructure that powers Argus, behind this page.
- 36M
- Compromised machines
- 5,698,026
- Employees with exposed credentials
- 15,839,002
- Domains in the dataset
- 500M+
- Compromised passwords
- 25B+
- Compromised session cookies
Attack infrastructure tracked right now
measured at 08/11, 05:45 PM- 43,334
- C2 servers
- 29,221
- PhaaS hosts
- 4,085
- ClickFix sites
active infostealers
phishing as a service
clipboard hijacking
How a credential leaves someone’s machine and ends up on a forum
No step requires the company to have been breached — the compromise happens on one person’s computer.
A machine gets infected
Almost always outside the perimeter: a pirated installer, a "crack", an attachment. It may be an employee’s personal laptop, or a supplier’s.
Copies the whole browser
Saved passwords, history, and — what matters most — session cookies. It takes seconds and leaves no trace in your SIEM, because nothing happened on your network.
The log is sold or published
It becomes a file on a forum, a Telegram channel or a closed market. The same log is resold several times, to different buyers.
The access asks for no password
With a valid session cookie the attacker never logs in — they resume a session someone already opened. Strong passwords and MFA are never consulted.
Families the base identifies by name
Not "generic malware": the log arrives attributed, and that is what makes dating and correlation possible.
- Lumma
- Sold as a service. Targets browsers, 2FA extensions and wallets.
- Acreed
- A recent family, already present in Brazilian samples this month.
- RedLine
- One of the most widespread of the decade. Credentials, cookies and wallets.
- Vidar
- Derived from Arkei. Steals credentials, cookies and screenshots.
- StealC
- Modular, sold as a service; mimics the behaviour of its predecessors.
- Rhadamanthys
- More sophisticated and modular, focused on crypto and credentials.
Some logs arrive with no family attributed by the source — those show up as generic, and the chart in the result reports that share honestly.
What shows up when you search
Everything masked on the server before it leaves here.
- Compromised machines
- How many, with employee and customer credentials counted separately.
- Active sessions
- Cookies still valid and on which services — what bypasses password and MFA.
- Identity surface
- VPN, ADFS, Citrix, webmail and portals found in the URLs.
- Related assets
- Subdomains and apps tied to the brand, found in the logs themselves.
- Sample forensics
- Password strength, the antivirus that was installed, programs on the machine.
- Credential sample
- Real rows, masked — password as an abstract shape, machine partially hidden.
Rather not type yours right now?
Our own house, with real data.