What it steals
Passwords saved in browsers, session cookies that keep users signed in, autofill data, cryptocurrency wallets, files from the desktop, and access tokens for applications such as Slack, Teams or VPN clients. Stolen session cookies are especially dangerous because they can let attackers in without the password or the MFA step, leading to account takeover.
How devices get infected
Pirated software and game cheats, fake browser updates, malicious ads in search results, fake CAPTCHA pages that ask users to paste commands, and phishing attachments. A common pattern is a personal computer, or a family member's computer, where an employee has also signed in to work accounts.
Why companies should care
Credentials stolen by infostealers have been behind major breaches. In 2024, attackers accessed many customer accounts on the Snowflake data platform using credentials stolen by infostealers, from accounts that did not have MFA enabled. Families such as Lumma, RedLine and Vidar are sold as a service, which makes these attacks cheap and widespread.
Reducing the risk
Use passkeys or other phishing resistant MFA, store passwords in a password manager rather than the browser, allow access to company systems only from managed devices through conditional access, keep EDR on every device and shorten session lifetimes. When an infection is found, reset the passwords and revoke all active sessions, not just the password.




