Technique
Infostealer
Also known as: Stealer Malware, Infostealer Malware
Malware designed to silently harvest saved credentials, browser cookies, session tokens, cryptocurrency wallets, and personal data from infected devices, then exfiltrate it to attackers within minutes of infection. Operating as Malware-as-a-Service (MaaS) platforms priced from $200-$250/month, infos…
Common attack flows
How it fits in a scam
Defense
How to defend against this
How to spot it
- Unexpected login alerts from services like Google or Microsoft from unfamiliar locations or devices
- Password reset emails you did not request
- Two-factor authentication prompts you did not initiate
- Unauthorized posts
- DMs
- or purchases from your accounts
- Friends or contacts receiving strange messages from your accounts
- Antivirus or security software mysteriously disabled or uninstalled
- Notification from a breach monitoring service that your credentials appeared in a stealer log dump
- Cryptocurrency wallet balances unexpectedly drained
- Being logged out of accounts simultaneously across multiple services
- Browser extensions you did not install
- or changed homepage and search settings
- Sessions appearing in account security dashboards from locations you have never visited
Tools you can use
Steps you can take
Seen in the wild
Where we’ve seen it
Further reading
Malwarebytes
Comprehensive infostealer guide covering types, targets, and protection
Red Canary
Detection methods and infostealer trends report
Kaspersky
RedLine used in 51% of infostealer infections 2020-2023
Deepstrike
Comprehensive 2025 report ranking top infostealer families by impact, with delivery methods and consumer statistics
eSecurity Planet
Reports 3.9 billion passwords compromised by infostealers, with 330 million credentials and 4.3 million devices infected in 2024
KELA Cyber
2025 epidemic report showing personal devices account for 65% of infections and technology sector most targeted at 14%
Vectra AI
Details how infostealers stole 1.8B credentials in 2025, session cookie MFA bypass, and FIDO2 passkey defense
Help Net Security
Flashpoint data: 11.1 million machines infected in 2025, 3.3 billion credentials traded on criminal markets
Vermont Federal Credit Union
Consumer-focused explainer of ClickFix fake CAPTCHA technique used to deliver infostealers
CyberDesserts
2026 overview covering ClickFix delivery, session cookie theft bypassing MFA, and Vidar 2.0 emergence after Lumma disruption
Malwarebytes
Comprehensive infostealer guide covering types, targets, and protection