
Infostealer
An infostealer is a piece of malware that secretly collects stored credentials, session data, and other personal information from a computer and sends it to criminals. The stolen data is usually resold in large bundles on illegal forums.
An infostealer is a piece of malware that installs itself unnoticed on a computer. Its sole purpose is to collect stored information and send it away. This includes passwords saved in the browser, stored credit card numbers, cookies, and files containing cryptocurrency keys. Unlike ransomware, an infostealer doesn’t destroy or lock anything. It specifically tries not to draw attention, because the longer it remains undetected, the more data it collects. Often it finishes within a few minutes and then deletes itself.
Why stolen passwords can hit entire companies
Infostealers are today one of the most important starting points for large-scale attacks. Criminals no longer need a complicated security vulnerability if they can simply buy a valid password. These passwords often come from an employee’s private laptop. Anyone who has saved their company access there opens a door for attackers into the corporate network.
So-called session cookies are particularly sensitive. These are small files that confirm to the browser: this user is already logged in. Anyone who steals such a cookie can impersonate the user without knowing the password. Even two-factor authentication with a code sent to a phone often no longer helps in this case, because that step had already been completed for the current session.
On top of that comes the sheer scale. Individual infections add up to collections containing billions of records, which are traded on underground forums. Security firms regularly report such discoveries. Buyers there sometimes pay only a few euros for a single set of credentials.
The journey from download to data package
The infection almost always begins with someone running a file themselves. Typical bait includes cracked software, alleged game cheats, fake update notifications, or email attachments. Also common are videos on platforms like YouTube that promise a free program and link to a download. Some campaigns even ask users to paste a copied command into a system window.
After that, the program works through a list of known storage locations. Browsers store passwords and cookies in fixed files, as do chat programs, email clients, and crypto wallets. The infostealer copies these files, often also takes a screenshot, and bundles everything together. The finished package is sent to a server controlled by the attackers, known in technical jargon as a command-and-control server.
What stands out is how professionally this business is organized. Many infostealers are rented out as a subscription, for a few hundred euros a month, including a user interface and support. This service is called malware-as-a-service. The buyer therefore doesn’t need to be able to program, only to distribute the file.
How to notice an infection and what helps
In the news, infostealers usually appear indirectly. When a report describes a data leak at a cloud provider or a hacked corporate network, the credentials used had often been captured on a private computer months earlier. Well-known names from such reports include RedLine, Lumma, or Vidar. Reports about servers seized in police operations frequently concern exactly these programs as well.
In everyday life, the theft is rarely noticed immediately. Early signs are logins from foreign countries, messages you didn’t write, or warnings from a service about new devices. Some password managers and browsers also alert you when your own credentials show up in a known collection.
The best protection is unspectacular. Only download software from official sources, install system updates promptly, and store passwords in a password manager instead of directly in the browser. A common misconception is that changing the password alone is enough. As long as the malware is still active, the new password will be captured too. The device must be cleaned first, followed by new passwords and logging out of all active sessions.