Ablaufschema in vier Stufen: getarnter Download auf dem Rechner, Durchsuchen von Browser-Passwörtern, Cookies und Krypto-Wallets, Versand des Datenarchivs an einen Server der Angreifer, Weiterverkauf der Zugangsdaten auf einem Marktplatz.

Infostealer Malware

Infostealer malware is malicious software that secretly copies stored credentials, passwords, and other personal information from a computer and sends them to criminals. The stolen data is then usually resold in large bundles.

Infostealer malware is a program that someone runs on a foreign computer without the user’s knowledge. Its sole purpose is to collect information and send it away. It searches for saved passwords, online banking credentials, credit card numbers, and files containing personal data. Unlike ransomware, which locks the computer and demands money, an infostealer wants to remain as unnoticed as possible. Users often notice nothing for months because nothing visibly changes on the computer. The name comes from English: “information stealer” simply means a thief of information.

Why stolen credentials are so valuable

A single password rarely opens just one door today. Many people use the same combination for multiple services. So whoever obtains the login credentials for a forum sometimes also gains access to the email account. And the email account is the master key, because “forgot password” functions can be used to take over further accounts.

Particularly sensitive are stolen session data, so-called cookies. These are small files that confirm to the browser: this user has already logged in. Whoever copies such files can log into an account without knowing the password. Even a confirmation via mobile phone no longer helps then, because the login already appears to be completed.

For companies, this is a serious risk. If an employee catches an infostealer privately, company access credentials sometimes end up in the data package as well. Security researchers regularly report attacks on large companies that began exactly this way. The actual breach then happens weeks later, using perfectly normal, valid credentials.

From click to data package

The path onto the computer almost always leads through a voluntary action. Someone downloads a cracked version of an expensive program. Or they install a supposed graphics driver update recommended by a video in the description. Fake browser extensions and email attachments are also common routes. The malware is often contained in a file that genuinely also does what was promised.

Once the program is started, it specifically searches known storage locations. Browsers store saved passwords in certain files, and the infostealer knows exactly where. Chat programs, gaming platforms, and cryptocurrency wallets are also targeted. Everything found is packed into an archive and sent over the internet to a server controlled by the attackers. The entire process often takes less than a minute.

Many of these programs are now rented out as a service. Criminals pay a monthly fee and receive the finished software plus a web interface for evaluation in return. This significantly lowers the technical barrier. The loot is resold in packages, often referred to as “logs,” and a single data record costs only a few euros on corresponding marketplaces.

Data breaches in the news and everyday protection

When the news reports on millions of leaked passwords, a large portion of them originate from infostealers. Such collections are not created by a single breach at one corporation. They are compilations from countless infected private computers. Services like “Have I Been Pwned” cross-reference such lists and show whether one’s own email address has been affected.

The most effective protection is unspectacular. Only install programs from official sources, and especially no cracked software. Use a separate password for each service, ideally via a password manager. And wherever possible, secure the login with a second factor.

A common misconception is that antivirus software always detects this kind of thing. However, infostealers are constantly slightly altered so that they appear new and unknown. Anyone who suspects they have been affected should not only change their passwords but also end all active sessions. Otherwise, the stolen cookies remain valid, and the attackers stay logged in despite the new password.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.