An infostealer is malware that quickly harvests saved passwords, browser cookies, crypto wallets and other secrets from an infected device and sends them to the attacker.
How an infostealer works
Infostealers usually arrive through cracked software, fake game cheats, malicious ads for popular programs, phishing attachments and fake CAPTCHA pages that trick users into pasting a command. Within seconds of launch they collect:
- passwords, autofill data and cards saved in browsers;
- session cookies and tokens, which let attackers enter accounts without a password or a second factor;
- crypto wallet files and browser extensions;
- Telegram, Discord, Steam, VPN and FTP credentials, screenshots and system details.
The collected data, called a “log”, is uploaded to the operator. Popular families such as RedLine, Raccoon, Vidar and Lumma are sold as a subscription service; Lumma’s infrastructure was disrupted by Microsoft and law enforcement in 2025.
Why infostealers matter for security
Infostealer logs are sold in bulk on underground markets and are one of the main sources of initial access for ransomware gangs and data thieves. In 2024 attackers used credentials stolen by infostealers years earlier to log into Snowflake customer accounts without MFA and steal data from companies such as Ticketmaster and AT&T. One infected home computer used for work can expose a whole company.
How to protect yourself
- Never install cracked software or run commands suggested by websites.
- Use MFA or passkeys; companies should bind sessions to devices and shorten session lifetimes.
- After an infection, change passwords from a clean device and sign out of all sessions.
- Do not store corporate credentials in personal browsers.