InfoStealers: The Silent Pickpockets of the Internet

  • AUGUST 27TH, 2025
  • 2min read
InfoStealers: The Silent Pickpockets of the Internet

Introduction

Infostealers are a type of malware designed to infiltrate computer systems to steal information. They exfiltrate various data, including login credentials, session cookies, financial info, sending it to a remote server controlled by cybercriminals. Cybercriminals also market infostealers as Malware-as-a-Service (MaaS), lowering the barrier of entry for bad actors. Infostealers spread like most other malware: through social engineering attacks, email, SEO poisoning, malicious links, botnets, etc.

What Information is Collected by Infostealers?

Infostealer malware can collect any, and all, information from an infected device and its browser, such as:

  • Login credentials: Usernames, passwords, and other authentication details like session cookies for various online accounts. We’re now starting to see infostealers exfiltrate 2FA tokens and passkeys.

  • Financial information: Credit card numbers, bank account details, and other financial data stored in the browser.

  • Identity data: Social security numbers, addresses, phone numbers, and other forms of PII.

Best Practice Against Infostealers

Here are some key methods for preventing infostealers from infiltrating your systems:

  • Spotting Social Engineering Attacks: Train staff to spot social engineering and use email security tools to defend against infostealers, often spread via phishing and malicious downloads.

  • Preventing Browser Synchronisation: This ensures that passwords to your corporate systems are not accessible through personal devices.

  • Utilising Advanced Identity Management and Access Control: These systems track behavior and react to suspicious activity by blocking or adding new verification methods.

  • Proactively Search for Logs: Proactively search infostealer markets and dark-web threat intelligence for company and employee logins, including hijacked accounts.

  • Incorporating Endpoint Detection and Response (EDR): EDR tools monitor for malware-based detection, quickly identifying new infostealer variants and stopping session-based detection bypass methods.

  • Leveraging Multi Factor Authentication: Though infostealers can bypass MFA via session cookies, MFA remains crucial. It acts as a failsafe, protecting data even if login credentials are compromised by an infostealer attempting a wider attack.

Explore more CIL Advisories

Review Bombing Attacks and Extortion

Review Bombing Attacks and Extortion

IntroductionMalicious actors use "review-bombing", a coordinated flood of fake, one-star reviews as an initial step for extortion. This high volume…

NOVEMBER 26TH, 2025

Read More
Synthetic Phishing: AI-Enabled Insider Impersonation

Synthetic Phishing: AI-Enabled Insider Impersonation

IntroductionThreat actors increasingly use artificial intelligence (AI) to impersonate trusted individuals such as executives, employees, or suppliers within organisations. These…

NOVEMBER 24TH, 2025

Read More
The Silent Security Threat: Data Hoarding

The Silent Security Threat: Data Hoarding

IntroductionThe greatest risk to your organization may be the sheer volume of data we hold, a practice known as Data…

NOVEMBER 19TH, 2025

Read More

Never miss a CIL Security Advisory

Stay informed with the latest security updates and insights from CIL.

InfoStealers: The Silent Pickpockets of the Internet

Contact Us

Message Sent!

Thank you for reaching out. We have received your message and will get back to you shortly.

Check your email for a confirmation from us.

Start a project

Project Request Submitted!

Thank you for your interest. Our team will review your project details and reach out to you soon.

Check your email for a confirmation from us.

We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. You can manage your preferences or learn more in our Cookie Policy .