Credentials-as-a-Service: Tracking Eleven Dark Web "Cloud" Brands
Between 1 August and 9 September we logged 82 dark web listings from eleven separate vendors renting access to stolen email credentials rather than selling it outright. Tiered pricing, daily delivery quotas, VIP support and, in five cases, a free trial. This is what the actor tracking shows and what it does not

A listing for stolen Hotmail accounts posted in late August offered a trial period. Sample files have been standard courtesy on these forums for years, but this was a time-limited trial of the kind you would find on a SaaS pricing page, sitting alongside tiers that ran from three days to lifetime access, a dedicated support handle, and a promise of daily delivery.
We started pulling on that thread and found ten other vendors doing the same thing at the same time.
What we collected
Between 1 August and 9 September 2026 our collection captured 82 listings across 21 days of activity, attributable to eleven distinct vendor identities. Nineteen listings state subscription tiers explicitly. Seven advertise a VIP level above the standard tier. Five offer a trial period.
The most common recurring claim is a daily volume commitment. "15,000+ fresh emails daily" appears across multiple vendors in near-identical phrasing; one operation advertises 20,000. Whether those numbers are honest is a separate question, and we have no way to verify them from listing text alone. What matters is that the vendor is willing to state a daily figure at all. A one-off sale does not require the seller to make any promise about tomorrow.

Image: Subscriptions listing stating daily volume, tier durations, and pricing
The eleven identities
The vendor handles we tracked:
shadowcloudsupport
LOLCLOUD,
MonkeyBaseCloud
DAISY CLOUD
SYCO CLOUD
Cloud_Panther
EliteCloudGroup
Jackal Cloud
ValidCloud
EagleClouud
BRADMAXCLOUD_BOT
We assess with moderate confidence that these are eleven separate operations rather than one actor running multiple personas. Posting rhythms, advertised data types, and batch volumes diverge in ways that would be difficult to sustain deliberately. shadowcloudsupport's 13 listings cluster into four days, in large segmented batches. LOLCLOUD's 12 listings spread across five days in batches of a few hundred accounts. That is a different operational tempo, and the product mixes do not overlap cleanly either.
The naming convention is the obvious shared feature. Every one of the eleven has built its brand around "cloud," which we read as positioning: it signals uptime and continuity to a buyer before they read the offer terms. EagleClouud takes the corporate imitation furthest, running a primary sales handle, a separate support bot, and a third handle dedicated to a single product line.

Image: EagleCloud listings, data derived from Stealer logs
Evidence of scaling supply
A subscription model only holds together if supply is continuous, and at least one vendor's advertised inventory grew visibly over a short window. DAISY CLOUD advertised 6,078 logs on 31 July, 10,791 on 7 August, and 14,277 on 9 August. That is a 135% increase in ten days, on the vendor's own numbers.
Three data points from one actor is thin evidence, and inventory claims are trivially inflatable. We flag it as consistent with growing upstream intake, not as proof of it.
The infection side of the chain shows the same service posture. A stealer marketed on 22 August advertises near-100% uptime, a web panel for monitoring collection, and 24/7 support. Malware-as-a-service and credential resale are converging on the same commercial vocabulary, which is unsurprising once both are competing for repeat customers rather than one-time buyers.
What this changes for defenders
The practical difference is exposure timing, and it cuts in two directions.
A credential sold once in a package may sit with a single buyer for weeks before anyone tries it. A credential entering a subscription delivery queue reaches every active subscriber on the next drop. We cannot put a firm number on how many subscribers that is, because none of the eleven advertise their customer count, but the structural point holds: subscription distribution shortens the gap between compromise and first use, and widens the set of people holding the credential.
That argues against periodic credential auditing as the primary control. Quarterly checks assume a slow market. Continuous monitoring of exposed credentials, paired with enforced rotation on detection, fits the observed distribution model better.
It also means listing counts should be treated carefully. If the same underlying stream is resold across a rotating subscriber base, identical credentials will surface in many listings under many vendor names, and totalling those listings will overstate the number of compromised accounts. For sizing this market, the count of distinct operations running the model is the more defensible figure. Right now, on our collection, that number is eleven.