Back to the glossary
    Malware & infrastructureCybersecurity glossary

    Infostealer

    Malware that silently steals credentials, cookies and browser data, packaging them for sale on the dark web as stealer logs.

    Full definition

    An infostealer is malware designed to silently steal the valuable information on an infected machine: passwords saved in the browser, session cookies, autofill data, cryptocurrency wallets and files. It acts in seconds and often deletes itself afterwards, so the victim notices nothing.

    The loot is packaged into stealer logs sold for low prices on dark web markets and messaging channels. A single log can include an employee's corporate credentials and valid cookies, letting a buyer walk into company systems past the password and MFA. The infected personal computer holding work logins is the critical scenario.

    Defense combines endpoint protection and blocking corporate passwords from being saved in personal browsers with dark web monitoring that detects when company credentials appear in those logs.

    What an infostealer does

    An infostealer does four things in order. It gets onto the machine, almost always through an attachment, a pirated software installer, a fake browser extension or a malicious ad. It harvests in seconds what the browser and the system already have stored: passwords, session cookies, autofill data, application tokens and cryptocurrency wallets. It sends that package to the operator's server. And in many variants it deletes itself to leave no trace.

    It does not encrypt or destroy anything: its business is information. That is why the victim rarely notices the infection, and the damage shows up weeks later, when the buyer of the log uses the credentials to get into the company's email, cloud or banking.

    How to protect against an infostealer

    Protection has three layers. On the device: updated antivirus or EDR, patched operating system and browser, and no pirated software or extensions from outside the official store. On identity: a password manager instead of browser storage, phishing-resistant multi-factor authentication, and closing active sessions at the first sign of suspicion, because a stolen cookie is worth more than the password.

    In the company: no corporate access from unmanaged personal devices, and dark web monitoring to learn when the organization's credentials show up in stealer logs and force a reset before anyone uses them. Training matters where the infection happens: most infostealers get in because a person ran something that looked legitimate.

    Infostealer vs. other credential-stealing malware

    A keylogger captures what the person types, in real time and over days; the infostealer does not wait for typing: it takes everything already stored in one pass, including the session cookies that bypass the password and MFA. A remote access trojan gives the attacker interactive control of the machine; the infostealer gets in, copies and leaves, often deleting itself. Ransomware encrypts and extorts in plain sight; the infostealer works in silence.

    Many families combine several of these functions, but the defining trait of an infostealer is the mass, silent extraction of credentials for sale as logs. That is why the specific defense is not just antivirus but knowing, as early as possible, which company credentials are already circulating.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.