166 terms · 75/46/45
Threat № 012 · class: malware

Infostealer

An infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the attacker and sends on what it gathers. When the job is done it can delete itself and disappear.

Term

description · examples · notes

An infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the attacker and sends on what it gathers. When the job is done it can delete itself and disappear.

Description

It arrives through cracks, fake installers, attachments or malicious advertising. It does not linger; the aim is not to settle in but to grab and vanish, often within seconds. Stolen session tokens are the real prize, because they give attackers access to accounts protected by two-factor authentication.

What is collected is sold on the black market and opens the door to bigger problems: account takeover, a break-in to the corporate network, ransomware. A large share of breaches begins with credentials some stealer gathered months earlier.

Examples

  • An employee downloads a crack for a program; the stealer takes every browser password and session token. The attacker walks into the business mailbox without a single obstacle.
  • High-profile users are a lucrative target: influencers, dissidents, political opponents, competitors.
  • Credentials taken from the machines of suppliers or development teams can put an entire infrastructure at risk.

Notes

  • A stolen session token is a bigger prize than a password, because using it bypasses MFA.
  • A password the browser remembered is a password the stealer can read.

Mentioned in the news

Composite
Wikipedia

Techniques

carried out with 6

Defenses

countered by 8