A cracked spy tool has a price. It is set by whoever packaged the installer, and it is collected from your browser. In June 2026 alone, AhnLab’s ASEC lab tracked four infostealer families (Remus, ACRStealer, LummaC2, Vidar) circulating inside cracks and keygens, pushed to the top of search results through SEO poisoning and hosted on ordinary file-sharing services like Mega and Mediafire.
An infostealer is a small program with one job: copy everything useful out of a browser (saved passwords, autofill data, payment details, session cookies) and ship it to its operator, who bundles the haul into a “log” and puts it up for sale.
For a marketing team, that browser is the business. It holds the ad accounts, the tracker, the affiliate network dashboards, and the payment methods behind all of them.
From a buying-side perspective, what separates infostealers from most security topics is that nobody has to break in. Someone on the team wanted a $200-per-month tool for free, ran the installer, and the installer wanted the browser.
The bill comes due in three parts: stolen marketing accounts are worth real money, two-factor authentication does not save a stolen session, and the fixes for a small team cost nothing except a few changed habits.
The short version:
- Stolen ad accounts circulate as a commodity. Push Security’s analysis of the malvertising ecosystem describes strong demand for reputable accounts: high spending limits, established billing, and a clean history make them ready-made vehicles for fraud.
- Cracked tools, “free” premium extensions, and template bundles are a recurring infostealer delivery route, and fake AI tools have joined the lure list. Mandiant tracked one campaign whose fake AI-generator ads reached over 2.3 million users in the EU alone.
- Session cookies bypass two-factor authentication by design: the cookie is proof of a login that already happened, so no second factor is ever requested.
- The strongest free defenses are a dedicated browser profile for ad accounts, an extension audit, individual logins instead of shared ones, and a periodic sign-out of all active sessions.
- None of this needs a security budget. It needs three habit changes: what you install, what you share, and where you sign in.
Why Stolen Ad Accounts Are Worth Real Money
Attackers put deliberate effort into taking marketing accounts, and the resale market explains why.
In January 2026, Push Security reported a significant increase in attacks aimed specifically at ad manager accounts, including phishing sites impersonating legitimate marketing tools such as Ahrefs and Calendly-themed lures aimed at marketing professionals.
The logic behind that effort is plainly commercial: a seasoned ad account carries high spending limits, saved billing, and a compliance history that makes platform fraud systems less suspicious of it.
All that accumulated trust is what an underground buyer pays for.
Google’s Threat Analysis Group traced a cluster of Vietnamese actors who hijacked marketing accounts to “either sell ads to other actors, or sell the accounts themselves” for profit.
Push Security notes forum listings advertised with the account’s age, billing history, and spend limits, the same attributes an agency would brag about to a client, and gives the example of a listing built around a two-year-old account with a $50k monthly spend history.
There is a second layer that buyers of these logs value: an ad account login is often also a single sign-on identity. The same Google or Microsoft account that opens the ad dashboard opens the mailbox, the shared drives, and every SaaS tool connected to it. Whoever holds that session holds far more than a campaign manager.
How a Cracked Tool Becomes an Infostealer Log
The delivery mechanics are unglamorous. A team member searches for a cracked build of a spy tool, an SEO suite, or a “lifetime” template pack.
SEO poisoning puts the download page high in the results. The archive arrives from a file-sharing host, and a familiar instruction rides along: disable your antivirus first, because cracks “trigger false positives.” That single instruction does most of the attacker’s work, because the person ends up running an unsigned executable with protection off, on the same machine where the ad accounts live.
What happens next is well documented. Microsoft’s June 2026 analysis of StealC shows the malware walking through Chromium browser profiles (Chrome, Edge, Brave, Opera) and Firefox-family data stores, extracting saved logins, autofill, payment data, session cookies, and even browser extension data such as wallet extensions.
The same report describes the division of labor: operators infect at scale, access brokers validate and monetize the credentials, then resell them at a premium to actors who want a foothold in a specific business.
The part that should worry a small team most is the visibility gap. As Microsoft puts it, the initial infection usually happens on an unmanaged or lightly protected device, so the first observable event is often someone else using valid credentials weeks later. There is no alert between “ran the installer” and “a campaign you did not create is spending your budget.”
A timeline makes the sequence easier to hold in mind, because every stage happens out of the team’s sight:
From “Free Tool” to Someone Else’s Campaign
The middle of this chain produces no alert, which is why the first signal a team gets is the last stage.
Download
A cracked tool arrives from an SEO-poisoned search result, with an instruction to switch antivirus off “to avoid false positives.”
Harvest
The infostealer copies saved passwords, session cookies, autofill and extension data, in seconds.
Sale
The haul is packaged as a log and listed on a marketplace. An access broker checks the ad account is live.
Entry
The buyer imports the session cookie and lands inside the account with no login and no second-factor prompt.
Invisible to the team: no alert fires anywhere in here
Often weeks pass between the harvest and the first use of the credentials
Damage
New users appear on the account, campaigns nobody created go live, and the budget drains.
First thing anyone notices
Sequence per AhnLab ASEC (crack and keygen delivery) and Microsoft Security (browser data theft, access-broker resale), 2026.
Why Two-Factor Authentication Does Not Stop a Stolen Cookie
Two-factor authentication protects one event: the login. When you sign in and pass the code check, the platform hands your browser a session cookie, a small token that says “this person already proved who they are.” From then on, the cookie is what gets checked, not you. That is why you do not re-enter a code on every page view.
A stolen cookie inherits all of that. When an infostealer lifts session cookies out of the browser’s data store, the buyer of the log imports them into another browser and resumes your session from their machine. The platform sees a valid, already-authenticated session, so by default no second factor is requested.
Major platforms do run extra checks on top (a sudden country jump or a mismatched device fingerprint can kill the session or force a re-login), which is why practiced attackers replay the cookie through a proxy near your location, from a browser profile dressed up to look like yours. Security teams call this session hijacking, or pass-the-cookie in its replay form, and it is the recurring mechanic behind account takeovers where the victim insists, correctly, that 2FA was switched on.
The practical consequences run in both directions:
- Two-factor authentication remains worth enforcing, because it still defeats attackers who only hold a password. It just has a boundary: it cannot protect a session that has already been issued.
- The controls that act on that side are different ones, and they are free: signing out of all active sessions (which invalidates the stolen cookies), reviewing the active-devices page your platform provides, and keeping ad-account sessions in a browser that cracked software never touches.
The Free-Tool Habit Inside Small Teams
Affiliate and small buying teams run on tooling priced for agencies. A spy tool here, an SEO suite there, a tracker plan, a creative service: the monthly stack can pass a junior buyer’s salary.
So, the workarounds became culture. Cracked builds circulate in chats, “free premium” extensions promise the paid feature set, and group buys split one subscription across dozens of strangers.
Each of those habits has a specific cost. The cracked build is the classic stealer carrier described above.
The unofficial extension runs inside the browser with whatever permissions it asked for, right next to your ad dashboards, and our guide to adware in paid traffic shows where that access leads: injected ads, rewritten affiliate links, stolen sessions. Group buys deserve a closer look than they usually get, because a recurring way these services deliver access is a shared browser profile or an extension that injects session cookies for the tool’s account.
Read that mechanic again: a session cookie passed between machines is the very thing that makes a stealer log valuable. A team that buys group-buy access has normalized the object attackers trade in, and has also handed its members’ browsers to an unvetted intermediary whose business is cookie distribution. Shared logins inside the team carry a milder version of the same problem: when five people use one account, the security of all five is the security of the least careful laptop, and there is no way to revoke one person without locking out everyone.
AI Tools Are the New Bait
The lure list has refreshed itself. Mandiant tracks a campaign it calls UNC6032 that has run fake “AI video generator” websites since at least mid-2024, impersonating known tools like Luma AI, Canva Dream Lab, and Kling AI. Thousands of ads, mostly on Facebook with a smaller run on LinkedIn, pointed to more than 30 such sites.
From a sample of just over 120 ads, EU transparency data showed a combined reach above 2.3 million users. Reach is an upper bound, since seeing an ad is not the same as running the payload, but the scale of the targeting is the point. Whatever prompt a visitor typed, the “generated video” downloaded as an executable carrying a dropper with infostealer components, exfiltrating credentials, cookies, and payment data.
Marketers make a receptive audience for this bait, because testing new AI tools is part of the job. Tool churn in this space is high, nobody recognizes every brand, and an unfamiliar name reads as normal rather than suspicious. Cracked “premium AI” bundles ride the same wave in forums and chats, promising lifetime access to tools that are subscription-only.
Platforms do act on this: Meta had been detecting and removing the UNC6032 ads and domains before Mandiant reported additional activity, and ad networks keep pulling these lures in moderation as they surface.
Attackers respond by registering fresh domains and pushing them into new ads, often within a day, the same evasion cycle we described in how to protect ad campaigns from malware traffic, which is why the durable defense sits with the person, as a team rule rather than a technology: a new AI tool gets checked for its real domain, gets tried in the browser without downloading anything executable, and never arrives as a .exe named like a video file.
Covering the Same Needs Without Cracked Software
If you work in an AI chat: the MCP connector
The honest limit: a token still sits on your disk. The win is one-click rotation and per-person scope, not immunity.
The needs behind the cracked stack are legitimate: competitor intelligence, creative production, automation, bid and volume guesswork. The unpaid routes to them do not have to run through unsigned installers.
For competitor research, the legal free tiers of major spy tools plus the platforms’ own transparency libraries cover most of what a small team actually uses, and we wrote a full guide on how to use spy tools properly without burning money or accounts.
Most of the rest is now inside the account. NIKO, the AI agent on the PropellerAds platform, creates, edits, and pulls up campaigns across Push, Popunder, Telegram Ads, Interactive Ads, and Paid Social Traffic through a conversation: it sets full targeting and dayparting, recommends rates for a given GEO and format, estimates how many clicks or impressions a budget will buy, and suggests a starting test budget.
Those last two are exactly what people reach for third-party scripts and scraped datasets to answer. PropellerAds’ own early figures put NIKO users at 11 times faster from registration to a first campaign draft, with 2 to 4 times more revenue than manually configured campaigns; those are the platform’s internal numbers from first adopters rather than an independent benchmark, so treat them as direction, not a forecast for your account.
Auto Creatives covers the creative side, turning your landing page into ready-made Push and In-Page Push creatives when you launch a new campaign (currently English-only, and worth reviewing after moderation rather than trusting blindly), while CPA Goal and Rule-Based Optimization handle the bid and budget decisions that third-party scripts otherwise chase.
If you already work in an AI chat all day, the PropellerAds MCP connector moves the same operations into Claude, ChatGPT, Gemini, or Cursor: list campaigns, create and edit them, manage rates and creatives, pull stats and balance.
What matters here is the credential model. You install one .mcpb file and paste an API token generated in Profile → API, so no login or password is involved, the AI provider never receives the token (it stays in a local config file on your machine and goes straight to PropellerAds), and you can revoke or rotate the token whenever you want, at which point the old value stops working immediately. The agent also acts only on what you ask it to do.
Note: a token in a local config file is still a secret sitting on your disk, so an infostealer on that machine can reach it. The difference from a shared password is what happens next: you rotate the token in account settings, and the stolen copy is dead, without disturbing anyone else on the team.
Locking Down a Small Team Without a Security Budget
Every control below is free, and each one maps to a specific attack from earlier in this article. None of them requires a security hire.
- Give ad accounts their own browser profile. Create a separate browser profile (or a separate browser) that opens ad platforms, trackers, and payment pages, and nothing else. Install zero extensions in it. Extensions in your everyday profile then live one wall away from the sessions that matter. What small teams usually underestimate is how much this one control buys: ten minutes of setup that shrinks both extension exposure and the blast radius of a bad download.
- Audit extensions quarterly, in every profile. Remove what nobody remembers installing, and treat “free premium” versions of paid extensions as installers of unknown code, because that is what they are. Ownership of legitimate extensions changes hands silently, so a clean install a year ago proves nothing today.
- Retire shared logins. Where a platform offers user roles or multi-seat access, give each person their own seat with the narrowest role that works. Where it does not, at minimum document who owns the account, keep the credential in a password manager rather than a chat, and rotate it when anyone leaves.
- Use a password manager and stronger second factors. Unique passwords per account end credential reuse. Passkeys (sign-ins tied to your device’s hardware, with nothing to type and nothing to phish) resist the fake login pages that app codes do not, where platforms support them. Remember the boundary from earlier: all of this protects logins, not issued sessions.
- Make session hygiene a calendar event. Once a month, and immediately after anything suspicious, use the platform’s “sign out of all sessions” and review its active-devices list. This is the one control that directly cancels stolen cookies.
- Agree on the executable rule. New tools get tried in the browser; nothing from a forum or a file-host runs on a machine that touches ad accounts. Pair the rule with a budget path for requesting the paid tool, so the rule survives contact with real work.
The matrix below pairs each habit with what it stops and, just as important, what it does not:
| Free control | Stops or shrinks | Does not cover |
|---|---|---|
| Dedicated ad-account browser profile | Extension exposure next to ad sessions, fallout from everyday browsing | A stealer already running on the device |
| Quarterly extension audit | Extensions that were sold or updated into something hostile | Malicious code outside the browser |
| Individual seats instead of shared logins | One compromised member exposing everyone, the no-revocation problem | Phishing aimed at an individual seat |
| Password manager plus passkeys | Credential reuse, password phishing | Hijack of an already-issued session |
| Monthly sign-out of all sessions | Stolen cookies from past infections | Re-theft tomorrow if the device is still infected |
| No-executables rule | The crack and keygen delivery route | Browser-based lures and phishing pages |
What This Does Not Fix
A few limits are worth stating plainly. Profile separation reduces extension exposure and contains careless browsing, but a stealer that is already running on the machine reads every profile on the disk.
It builds a wall inside the house; a compromised device is the whole house. Attacker-in-the-middle phishing pages capture sessions after the victim passes 2FA, which is why the earlier point about passkeys matters more each year. Freelancers’ and contractors’ personal laptops sit outside anything the team can audit, and a log from one of those machines looks identical to a log from yours.
Detection is the weakest link of all. A team cannot see its credentials being sold; it sees consequences: a login alert from a country nobody is in, a campaign nobody created, commissions that stop matching the tracker.
When that happens, act in this order from a known-clean device: change the password, sign out all sessions, check the account for added users and changed billing, then contact the platform’s support to freeze activity.
What no support team can do is un-sell a log, so speed on your side matters more than a perfect diagnosis.
FAQ
What exactly is in an infostealer log?
Typically everything exportable from a browser in a few seconds: saved passwords, autofill data including payment cards, session cookies for every logged-in site, browser extension data, plus files matching patterns the operator set (wallet files, documents with “password” in the name). Logs are sold in bulk on marketplaces and Telegram channels.
I have 2FA on everything. Am I covered?
Against password theft, largely yes. Against session hijacking, no: a stolen session cookie is accepted after authentication, so no code is requested. Keep 2FA, add session hygiene (regular sign-out-all-sessions), and prefer passkeys where supported.
Are browser extensions safe to use for marketing work?
Signed extensions from official stores, with sane permissions, from developers you can name: reasonable risk. “Free premium” builds and anything installed outside the store: unknown code inside the browser that holds your ad sessions. Keep working extensions out of the profile that opens ad accounts, and audit quarterly.
Is group-buy access to spy tools risky beyond the terms-of-service issue?
Yes, and the risk sits in how the access is delivered. Group-buy services often hand out shared session cookies or their own extension, which puts an unvetted intermediary inside your browser and normalizes passing live sessions between machines, the same object infostealer markets trade in.
We already ran a cracked tool. What now?
Treat every credential and session in that browser as exposed. From a different, clean device: change passwords starting with email and ad accounts, sign out all sessions everywhere, check ad accounts for added users, new campaigns, and billing changes, and notify the platforms. Then rebuild the affected machine rather than trusting an antivirus scan that the installer asked you to disable.
What to Do This Week
The whole infostealer defense for a small marketing team fits in roughly two hours. Create a clean browser profile and move your ad platform, tracker, and payment logins into it. Sign out all sessions on every account that matters, so any cookie stolen in the past stops working today. Uninstall every extension nobody can vouch for. Replace the shared logins you can, document the ones you cannot, and agree on the executable rule with an actual budget path attached.
The “free” marketing stack is a line of credit. The lender is whoever packed the installer, the collateral is everything your browser knows, and the bill tends to arrive as someone else’s campaign spending on your card. Settle it before it is issued: the paid tier of any tool is cheaper than an aged ad account with your billing history behind it.
Join our Telegram for more insights and share your ideas with fellow affiliates!