Infostealer
An infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the attacker and sends on what it gathers. When the job is done it can delete itself and disappear.
Term
description · examples · notesAn infostealer has one basic role: to collect your credentials. Saved browser passwords, cookies and session tokens, autofill data, crypto wallet keys — all of it is of interest. It stays in contact with the attacker and sends on what it gathers. When the job is done it can delete itself and disappear.
Description
It arrives through cracks, fake installers, attachments or malicious advertising. It does not linger; the aim is not to settle in but to grab and vanish, often within seconds. Stolen session tokens are the real prize, because they give attackers access to accounts protected by two-factor authentication.
What is collected is sold on the black market and opens the door to bigger problems: account takeover, a break-in to the corporate network, ransomware. A large share of breaches begins with credentials some stealer gathered months earlier.
Examples
- An employee downloads a crack for a program; the stealer takes every browser password and session token. The attacker walks into the business mailbox without a single obstacle.
- High-profile users are a lucrative target: influencers, dissidents, political opponents, competitors.
- Credentials taken from the machines of suppliers or development teams can put an entire infrastructure at risk.
Notes
- A stolen session token is a bigger prize than a password, because using it bypasses MFA.
- A password the browser remembered is a password the stealer can read.
Mentioned in the news
- 25. JUL 2026. Infostealeri kao gorivo za velike sajber napade →
- 20. MAJ 2026. VoidStealer zaobilazi Chrome zaštitu i krade podatke iz browsera →
- 7. MAJ 2026. Remus malware zaobilazi zaštitu u Chromium browserima →
- 15. APR 2026. Novi ClickFix napad na macOS koristi Script Editor za tišu isporuku Atomic Stealer-a →
- 4. APR 2026. Lažni Claude Code repozitorijumi šire Vidar i GhostSocks malware →
- 4. APR 2026. Nova DeepLoad kampanja spaja ClickFix i AI prikrivanje malwarea →
- 4. APR 2026. Lažni ChatGPT ad blocker dodatak krade privatne razgovore korisnika →
- 2. APR 2026. Ukradeni logini postali su osnova za ransomware i državne sajber napade →
- 29. MAR 2026. Cloudflare ClickFix kampanja širi Infiniti Stealer na macOS uređaje →
- 29. MAR 2026. Zlonamerne ekstenzije kradu AI razgovore u prompt poaching napadima →
- 29. MAR 2026. GhostClaw malware cilja macOS i AI razvojna okruženja radi krađe lozinki →
- 23. MAR 2026. Copyright phishing kampanja koristi PureLog Stealer i fileless izvršavanje →
- 23. MAR 2026. VoidStealer koristi debugger trik za krađu Chrome master ključa →
- 14. MAR 2026. Storm-2561 širi trojanizovane VPN klijente kroz SEO poisoning i krade pristupne podatke →
- 13. MAR 2026. Storm-2561 koristi lažne VPN klijente za krađu korporativnih kredencijala →
- 24. FEB 2026. ClickFix infostealer koristi lažni CAPTCHA mehanizam za infekciju →
- 17. FEB 2026. Zlonamerna Chrome ekstenzija krade 2FA kodove i podatke iz Facebook Business Manager-a →
- 15. FEB 2026. Zlonamerne Chrome ekstenzije uhvaćene u krađi podataka korisnika →
- 14. FEB 2026. Claude LLM artefakti zloupotrebljeni za distribuciju Mac infostealera u ClickFix napadu →
- 13. JUL 2026. Trojanac u Visual Studio projektima ostavlja zamke za razvojne inženjere →
- 18. JUN 2026. Kada su na meti istraživanja, Kina cilja medicinu, AI i vojni sektor →
- 5. JUN 2026. IronWorm i Miasma gađaju npm: developeri postaju sve vrednija meta →
- 30. MAJ 2026. Chrome svim korisnicima uključio zaštitu kolačića →
- 7. MAJ 2026. CloudZ RAT zloupotrebljava Windows Phone Link za krađu kredencijala i OTP kodova →
- 7. MAJ 2026. Quasar Linux RAT cilja developere i kredencijale za softverski lanac →
- 30. APR 2026. Europol IOCTA 2026: AI, enkripcija i proxy servisi šire sajber kriminal →
- 30. APR 2026. Popularni PyPI paket elementary-data kompromitovan za širenje infostealera →
- 15. APR 2026. Krađa sesionih kolačića: zašto MFA nije dovoljna posle prijave →
- 28. MAR 2026. ESET predstavio eCrime izveštaje za praćenje ransomware i infostealer pretnji →
- 11. MAR 2026. Shub malver širi se kroz lažne macOS aplikacije za čišćenje sistema →
- 4. MAR 2026. Kako piratski softver pretvara zaposlene u distributere malvera →
- 29. JAN 2026. Keyloggeri: kako rade i kako se u praksi braniš →
Techniques
carried out with 6Techniques used to carry it out. Select one to open its page.
Defenses
countered by 8How it is defended against. Select one to open its page.