
AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.
Infostealers take saved passwords, session cookies and crypto wallet data in one sweep. Changing passwords on an infected machine is not enough: clean the device first, then rotate credentials and kill sessions from a clean one.
01 / Signs you may be infected
Infostealers are malware built to copy credentials and hand them to criminals. Microsoft's June 2026 analysis of the StealC family lists what one stealer can take: browser passwords and cookies, SSO tokens, saved card details, cryptocurrency wallet data, email client logins, VPN and FTP credentials, gaming accounts, screenshots and selected files.
Many infections are silent. Clues include:
- You recently installed cracked software, a game cheat, or a download reached through an ad or search result.
- You followed on-screen instructions to paste a command into the Windows Run box (a trick Microsoft calls ClickFix) or accepted a fake browser update.
- Accounts show logins, password-reset emails or messages you did not send.
- Your email appears in stealer-log data on Have I Been Pwned.
The UK NCSC adds general warning signs: a device that becomes sluggish, reboots unexpectedly or shows unfamiliar pop-ups.
02 / Why a password change alone fails
When you log in, a site gives your browser a session cookie so you do not have to sign in again. Microsoft notes that stealers grab these cookies and tokens, which can let an attacker bypass multi-factor authentication. A stolen session can stay valid until the service ends it, so the attacker may remain logged in after you pick a new password.
Reset from an infected machine and you may simply hand the new password to the same malware.
That is why the order matters: clean first, then rotate, then sign out every session.
03 / Step one: clean or wipe the device
Disconnect the suspected machine from sensitive accounts and do not log in to anything new on it. The NCSC's recovery guidance for PCs and laptops is to update the system, run a full antivirus scan and follow its advice, and if that does not resolve the problem, wipe the device and reinstall the operating system. For phones and tablets it calls a factory reset the safest fix.
- Restore files only from a backup made before the infection, so you do not reinstall the malware.
- Do not restore browser profiles or password-manager exports that were on the infected machine.
- If you cannot do this yourself, get professional help.
04 / Step two: rotate passwords from a clean device
Using a device you trust, change passwords starting with the accounts that can reset others: your main email, then your password manager, banking, work accounts and cloud storage. Then work through everything else saved in the infected browser. Any password reused elsewhere must change everywhere.
Have I Been Pwned lets you see which websites your email appeared against in stealer logs: sign up for its free notification service, verify the address, and the domain list is shown on the verification page. That list is a good checklist. Also search your address for the Operation Endgame 4.0 breach, which HIBP added on 18 June 2026 with 4.3 million email addresses and passwords recovered during the law-enforcement takedown of SocGholish and StealC infrastructure.
05 / Step three: sign out every session
- Google: in your Google Account, open Security, then Manage all devices, and sign out of any device you do not recognise or no longer trust.
- Microsoft: in Advanced security options, use Sign out everywhere. Microsoft says this can take up to 24 hours and does not cover Xbox consoles, which you sign out separately.
- Other services (Discord, social media, gaming, shopping, crypto exchanges): look for a devices, sessions or security page and sign out of all other sessions. Where no such option exists, contact the service's support.
- Review connected apps and API keys, and remove anything you did not add.
06 / Step four: upgrade to passkeys and MFA
Turn on multi-factor authentication everywhere it is offered, and use passkeys where you can. Google describes passkeys as unlockable only with your fingerprint, face or screen lock, and says they cannot be shared, copied or written down, which gives stronger protection against phishing. CISA calls FIDO/WebAuthn authentication the only widely available phishing-resistant method, because it blocks a login attempt made on a fake site.
Remember that MFA does not protect a session that was already stolen, which is why step three comes first.
07 / Crypto wallets
If a software wallet, browser wallet extension or seed phrase was ever on the infected machine, treat it as compromised. The Security Alliance (SEAL) wallet-security framework advises creating a new, secure wallet and moving all assets to it immediately. Do this from a clean device, and give the new wallet a brand-new seed phrase.
- Revoke sessions and rotate API keys on any exchange accounts.
- Ignore anyone who contacts you offering to recover stolen crypto; genuine help will not come from unsolicited messages.
- Report theft to the police or your national cybercrime portal, such as IC3 in the US or cybercrime.gov.in in India.
Source log / 2026-0929-GI
- Microsoft Security Blog — StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them (24 Jun 2026) Primary
- NCSC — Hacked device: action to take Primary
- Have I Been Pwned — Operation Endgame 4.0 (added 18 Jun 2026) Primary
- Troy Hunt — Experimenting with Stealer Logs in Have I Been Pwned (13 Jan 2025) Primary
- Google Account Help — See devices with account access Primary
- Microsoft Support — How to sign out of your Microsoft account everywhere Primary
- Google Account Help — Sign in with a passkey instead of a password Primary
- CISA — More than a Password (MFA) Primary
- Security Alliance (SEAL) — Seed Phrase Management Secondary