Infostealer
Malware that silently steals credentials, cookies and browser data, packaging them for sale on the dark web as stealer logs.
Full definition
An infostealer is malware designed to silently steal the valuable information on an infected machine: passwords saved in the browser, session cookies, autofill data, cryptocurrency wallets and files. It acts in seconds and often deletes itself afterwards, so the victim notices nothing.
The loot is packaged into stealer logs sold for low prices on dark web markets and messaging channels. A single log can include an employee's corporate credentials and valid cookies, letting a buyer walk into company systems past the password and MFA. The infected personal computer holding work logins is the critical scenario.
Defense combines endpoint protection and blocking corporate passwords from being saved in personal browsers with dark web monitoring that detects when company credentials appear in those logs.
Related terms
Leaked credentials
Usernames and passwords exposed in breaches or stolen by malware, circulating on the dark web. They are the raw material of initial access to companies.
Session hijacking
Stealing the cookie or token that keeps an authenticated session open. It grants entry without a password and without a second factor.
Dark web monitoring
Continuous surveillance of breaches and criminal markets to detect exposed company credentials or data, and react in hours instead of months.
Malware
Any software designed to damage, spy on or take control of a system without authorization. It almost always needs a person to let it in.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.