Skip to content

Infostealer

Definition

An infostealer is malware that collects passwords, session cookies, browser data and files stored on infected devices and sends them to criminals who sell them as logs.

Also known asStealerInformation stealerStealer malware

Updated:

Compromised identities3 new hits
m.hu•••@beispiel-gmbh.atStealer log, 2 h agoEmployee
Microsoft 365 session cookieStealer log, 5 h agoEmployee
k.wa•••@gmx.atCombolist, 3 days agoCustomer

Visuals show sample data.

How blacklens.io covers this

An infostealer is a class of malware that, after infecting a device, quietly collects data and sends it to the attackers: passwords saved in the browser, session cookies and tokens, autofill data, credit card details, crypto wallets, files from the desktop and system information. The result, a so-called stealer log, is sold on underground markets or distributed via messenger channels.

Why infostealers matter

Infostealers are now one of the most common causes of compromised corporate accounts. The reason is the mixing of private and work: an employee logs in to Microsoft 365 or the VPN portal on a private laptop, someone installs a cracked game, the stealer runs for two minutes, and the session to the company is in the log. Session cookies are particularly dangerous because they bypass MFA: whoever holds the cookie is already logged in. Families such as RedLine, Raccoon, Vidar and Lumma have infected millions of devices; takedowns such as Operation Endgame have disrupted individual networks but not ended the business model.

How infostealers work

  1. Distribution: cracked software, fake installers, malicious advertising, phishing attachments, links on video platforms and chat services.
  2. Collection: the stealer reads browser databases (Chrome, Edge, Firefox), password manager extensions, email and FTP clients, VPN configurations and files.
  3. Exfiltration: the package contains passwords with login URL, cookies with expiry date, hardware fingerprint, operating system, installed antivirus software, IP address and location.
  4. Exploitation: logs are searched by domain. Access to corporate portals goes to initial access brokers; customer data is used for account takeover and fraud.

The stealer itself often does not stay on the device. That is why the infection is frequently noticed only once the data is already in circulation.

How blacklens.io addresses infostealers

blacklens.io's dark web monitoring evaluates stealer logs and attributes hits to your domains: compromised identities with an indication of whether password, cookie or personal data are affected, and compromised devices with IP, hostname, operating system, antivirus list, stealer path, infection date and location. Hits are classified automatically as employee or customer. Stolen session cookies are assessed by cookie name against the Open Cookie Database; expired cookies are archived automatically. Matching runs every 24 hours by default.

Does MFA protect against infostealers?

Only partly. MFA protects the password, not the active session. A stolen session cookie allows access without a new login until the session expires or is revoked. Short session lifetimes, device-based conditions and revoking sessions after a hit are therefore important.

What should you do when a device appears in a stealer log?

Change all passwords stored on the device, revoke active sessions for Microsoft 365, VPN and SaaS services, rebuild the device (stealers often download additional malware) and check whether it is a private device with access to corporate services.

Are Macs and smartphones affected too?

Yes. Windows is affected most often, but infostealers exist for macOS, and Android banking trojans work on the same principle. The risk lies less in the operating system than in the use of private devices for corporate access.

See which of these apply to your company.

The free exposure check shows in seconds which systems, technologies and dark web traces of your company are publicly visible.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings