Research by Flare demonstrates that up to 5% of infostealer malware victims are themselves threat actors, enabling attribution by linking stolen authenticated sessions from criminal forums to real-world identities. The methodology, presented at BSides Tallinn 2026, automates the process of mapping session cookies and device information from stealer logs to underground accounts and extracting identifying details from the infected machines.