Infostealer
Malware that silently steals credentials, cookies and browser data, packaging them for sale on the dark web as stealer logs.
Full definition
An infostealer is malware designed to silently steal the valuable information on an infected machine: passwords saved in the browser, session cookies, autofill data, cryptocurrency wallets and files. It acts in seconds and often deletes itself afterwards, so the victim notices nothing.
The loot is packaged into stealer logs sold for low prices on dark web markets and messaging channels. A single log can include an employee's corporate credentials and valid cookies, letting a buyer walk into company systems past the password and MFA. The infected personal computer holding work logins is the critical scenario.
Defense combines endpoint protection and blocking corporate passwords from being saved in personal browsers with dark web monitoring that detects when company credentials appear in those logs.
What an infostealer does
An infostealer does four things in order. It gets onto the machine, almost always through an attachment, a pirated software installer, a fake browser extension or a malicious ad. It harvests in seconds what the browser and the system already have stored: passwords, session cookies, autofill data, application tokens and cryptocurrency wallets. It sends that package to the operator's server. And in many variants it deletes itself to leave no trace.
It does not encrypt or destroy anything: its business is information. That is why the victim rarely notices the infection, and the damage shows up weeks later, when the buyer of the log uses the credentials to get into the company's email, cloud or banking.
How to protect against an infostealer
Protection has three layers. On the device: updated antivirus or EDR, patched operating system and browser, and no pirated software or extensions from outside the official store. On identity: a password manager instead of browser storage, phishing-resistant multi-factor authentication, and closing active sessions at the first sign of suspicion, because a stolen cookie is worth more than the password.
In the company: no corporate access from unmanaged personal devices, and dark web monitoring to learn when the organization's credentials show up in stealer logs and force a reset before anyone uses them. Training matters where the infection happens: most infostealers get in because a person ran something that looked legitimate.
Infostealer vs. other credential-stealing malware
A keylogger captures what the person types, in real time and over days; the infostealer does not wait for typing: it takes everything already stored in one pass, including the session cookies that bypass the password and MFA. A remote access trojan gives the attacker interactive control of the machine; the infostealer gets in, copies and leaves, often deleting itself. Ransomware encrypts and extorts in plain sight; the infostealer works in silence.
Many families combine several of these functions, but the defining trait of an infostealer is the mass, silent extraction of credentials for sale as logs. That is why the specific defense is not just antivirus but knowing, as early as possible, which company credentials are already circulating.
Related terms
Leaked credentials
Usernames and passwords exposed in breaches or stolen by malware, circulating on the dark web. They are the raw material of initial access to companies.
Session hijacking
Stealing the cookie or token that keeps an authenticated session open. It grants entry without a password and without a second factor.
Dark web monitoring
Continuous surveillance of breaches and criminal markets to detect exposed company credentials or data, and react in hours instead of months.
Malware
Any software designed to damage, spy on or take control of a system without authorization. It almost always needs a person to let it in.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.