← All terms

Infostealer

An infostealer is malware that silently harvests saved passwords, cookies and session tokens from a device and sells them into the criminal economy.

An infostealer is a class of malware built for one job: sweep an infected device for everything that grants access — saved browser passwords, session cookies, autofill data, crypto wallets, VPN configurations, authentication tokens — and upload it to the attacker within seconds. Unlike ransomware, an infostealer wants to stay invisible; many delete themselves after the grab. The stolen bundle, called a "log," is sold on marketplaces for a few dollars, which makes infostealers the industrial supply side of credential harvesting: one infection can expose every account a person has ever signed in to on that machine.

How it works

The delivery is usually social engineering rather than an exploit: cracked software and game cheats, fake browser or driver updates, malicious ads, and email attachments are the classic lures. Once executed, the stealer parses browser credential stores and cookie databases, grabs files matching patterns like "passwords.txt," and exfiltrates the log — often in under a minute. The cookies matter as much as the passwords: a fresh session token lets an attacker step into an account after multi-factor authentication has already been completed, no login prompt required. Logs are aggregated, indexed by corporate domain, and resold — an initial access broker searching for "yourcompany.com" can buy a working VPN credential harvested months earlier. Unmanaged personal devices are the blind spot: an employee who signs in to a work account, or syncs work credentials into a personal browser profile, extends the corporate attack surface to a machine the security team has never seen — the failure mode behind third-party incidents like Okta's 2023 support system breach.

How to defend against it

Block what you can: keep unmanaged devices away from corporate credentials, restrict personal browser-profile sync on work machines, and use EDR to catch known stealer families. Devalue what you can't block: passkeys and hardware-bound tokens don't yield a reusable secret, short session lifetimes shrink the value of stolen cookies, and breached-credential monitoring catches your domain in fresh logs. And train for the delivery layer — "free" software and fake updates belong in awareness training and phishing simulations, because the infection is almost always a human decision.

Related terms

Credential HarvestingCredential harvesting is the collection of usernames and passwords at scale, usually through fake login pages, phishing kits or infostealer malware.Credential StuffingCredential stuffing is an automated attack that tries username-password pairs stolen from one breach against many other sites, exploiting password reuse.Account Takeover (ATO)Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.KeyloggerA keylogger is software or hardware that secretly records keystrokes to steal passwords, messages, and card numbers, feeding credential-based attacks.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo