GlossarySecurity awareness

Infostealer

Short answer

An infostealer is malware designed to steal saved passwords, session cookies, browser data and other credentials from an infected device and send them to attackers. The stolen data, known as logs, is sold in criminal markets and is a leading cause of account takeovers and corporate breaches.

What it steals

Passwords saved in browsers, session cookies that keep users signed in, autofill data, cryptocurrency wallets, files from the desktop, and access tokens for applications such as Slack, Teams or VPN clients. Stolen session cookies are especially dangerous because they can let attackers in without the password or the MFA step, leading to account takeover.

How devices get infected

Pirated software and game cheats, fake browser updates, malicious ads in search results, fake CAPTCHA pages that ask users to paste commands, and phishing attachments. A common pattern is a personal computer, or a family member's computer, where an employee has also signed in to work accounts.

Why companies should care

Credentials stolen by infostealers have been behind major breaches. In 2024, attackers accessed many customer accounts on the Snowflake data platform using credentials stolen by infostealers, from accounts that did not have MFA enabled. Families such as Lumma, RedLine and Vidar are sold as a service, which makes these attacks cheap and widespread.

Reducing the risk

Use passkeys or other phishing resistant MFA, store passwords in a password manager rather than the browser, allow access to company systems only from managed devices through conditional access, keep EDR on every device and shorten session lifetimes. When an infection is found, reset the passwords and revoke all active sessions, not just the password.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub