Explainer
Infostealers
Malware that harvests saved passwords, session cookies, tokens and crypto wallets from browsers and apps, then sells them as ready-made access.
In this section
What it is
An infostealer is malware built to grab credentials and other valuable data from an infected computer and send it to the attacker, usually within seconds of running. Most are sold as malware-as-a-service: a developer rents the stealer and a control panel to customers, who run their own campaigns. Microsoft reported that the Lumma developer offered tiered subscriptions ranging from $250 to $20,000.
How it gets in
Stealers typically arrive through lures that persuade the user to run something: cracked software, fake installers promoted in search ads, malicious attachments, fake browser updates, or files delivered by loader malware. Because many infections happen on personal or unmanaged devices where employees also sign in to work accounts, the resulting theft often reaches corporate systems.
What it steals
Typical targets are browser-saved passwords, autofill data, session cookies and tokens, cryptocurrency wallets, and data from messaging, VPN and developer tools. According to Microsoft, Lumma went after passwords, credit cards, bank accounts and crypto wallets. Session cookies are especially valuable because they can let an attacker reuse a signed-in session without needing the password or an MFA prompt.
Notable families in 2025-2026
- Lumma: Microsoft said it found more than 394,000 infected Windows computers between March and May 2025, before a May 2025 action seized about 2,300 domains.
- Rhadamanthys: The Hacker News, reporting Operation Endgame results from November 2025, said investigators identified 525,303 infections across 226 countries and territories between March and November 2025.
- StealC: targeted in the June 2026 phase of Operation Endgame, which Eurojust said neutralised 326 servers and recovered 27 million compromised data sets across StealC, Amadey and SocGholish.
Takedowns disrupt but rarely end these services; operators often rebuild infrastructure within weeks.
How stolen logs are used
The output of each infection, known as a log, is sold on criminal markets and messaging channels or used directly. Buyers use logs for account takeover, fraud and crypto theft, and initial access brokers sift them for corporate VPN, SSO and cloud credentials that can be resold to ransomware affiliates. A single stolen session from an administrator can be enough to start a much larger intrusion.
Detect and contain
Detection signals
- Sign-ins reusing an existing session from a new device, country or network provider
- Unsigned or unknown binaries reading browser credential and cookie stores
- Developer, cloud or SSO tokens used from unexpected locations shortly after a download
Reduce the blast radius
- Phishing-resistant MFA (FIDO2/passkeys), starting with admins
- Short session lifetimes, token binding where available, and session revocation after any infection
- Block unmanaged devices from corporate SSO and disable browser password saving for work accounts
Questions people ask
What is an infostealer?
An infostealer is malware that collects saved passwords, browser cookies, session tokens, autofill data and crypto wallets from an infected device and sends them to criminals. It is usually rented as a service and spread through fake software downloads or phishing. The stolen data is sold or used for account takeover, fraud and breaking into company networks.
Can antivirus detect infostealers?
Often, but not reliably. Stealers are repackaged frequently to evade signatures, and many run, steal data and exit within seconds, so damage can occur before detection. Endpoint detection tools that watch behaviour, such as unknown programs reading browser credential stores, do better. Because infections often happen on unmanaged personal devices, identity controls matter as much as antivirus.
What should I do if my computer had an infostealer?
Clean or rebuild the device first, then change passwords from a different, clean device. Sign out of all sessions for important accounts, since stolen cookies can keep working after a password change. Move to passkeys or app-based MFA where possible, check crypto wallets, and tell your employer if you used work accounts on that machine.
Does MFA stop infostealers?
Not completely. MFA blocks attackers who only have your password, but many stealers also take session cookies from a browser that is already signed in. Replaying a valid cookie can bypass the MFA step. Shorter session lifetimes, device-bound sessions and revoking sessions after an infection reduce the risk.
Desk coverage