top of page

The Growing Threat from Infostealers

Infostealers are a relatively new type of malware designed to steal confidential information from infected devices. Their rise began in 2018 and has accelerated every year, reaching a staggering 100 million infected PCs globally by 2024.

This is due to their strong commercial focus, they are key components of a sophisticated and widespread cybercrime industry.

The main goal of infostealers is to locate and exfiltrate sensitive information and sell it to other cybercriminals on dark web markets.

So, how do you get infected?!

- Pirated software such as free licenses for photoshop, video game cheats, mods for video games, etc

- ⁨Supply chain attacks from hijacked NPM packages,  malicious Visual Studio extensions, open-source software, or even infected commercial software

- From Google Ads when you search for software and install from a malicious ad appearing at the top of search results

- ⁨Fake Captcha/System update (ClickFix) that takes advantage of social engineering and human trust

- Someone shared a link
in a game chat, Discord,
Whatapp, Facebook, or X

image.png
image.png
image.png
Picture 1.jpg
image.png
image.png

What information do infostealers steal?

Each infected device's data stored with such folder tree structure
folder_structure_sample.jpg
Infostealers steal data from across the victim's system, including browser autofill data, passwords, session tokens, credit cards, and more.
comp_info_blured.jpg
passwords_blured.jpg

Does 2FA Prevent Account Exposure? (No)

Browser cookies are used to represent an already authenticated web session, the method of original authentication does not matter, whether it was a passkey, MFA-validated, or logged-in using Single Sign-On (SSO). One stolen cookie is all it takes to bypass the entire authentication and login process. Users “fingerprints” are included with the credentials too so criminals can easily bypass attempts to detect fingerprint mismatches too.
market.jpg
screen1.jpg

The Personal and Business Damage of an Infostealer Leak

Personal Damage:

Unauthorized access to documents: Gmail, Outlook, Dropbox, iCloud
(mostly used to get access to other services, sell account or send spam)
 
Steel money from: Crypto wallets, Paypal, Casinos, Wise, Revolut, Banks

Documents from desktop used for brute-force attacks on crypto wallets

Steal digital assets from Games: Steam, Riot Games, Epic Games, Minecraft, etc

Social media: Facebook, Instagram, X, Netflix
Messengers: Telegram, Whats'up, Discord
used for reselling accounts or for malware spreading

Services: Uber, Axis, Ring, VPN, Vodafone, O2, ChatGPT, Amazon
Used to collect private data and to make fraudulent purchases using your account.

Sensitive data: Tinder, Pornhub, Adultfriendfinder, Baidu, Onlyfans, DNA collections, other medical services or Government sites for tax reports etc
Used for blackmail and fraud
Business Damage:

Unauthorized access to documents: Webmail, Jira, Zendesk, DropBox

Corporate access: SSO(okta, microsoft), VPN, SSH keys/certs

Corporate Messengers: Slack, Teams, Discord, Zoho, CRM/ERP systems

Other services: Github, AWS, SnowFlake, ChatGPT, Godaddy, Linkedin
 

Historical Infostealer Leaks:

Only in 2024 these
companies were hacked
by account takeover attacks
gained access to
SnowFlake cloud DB
using stolen credentials
harvested from
infostealer infection 

For instance, a Slack account cookie bought on the dark web for $10 led to the compromise of Electronic Arts 780GB game source codes.
ChatGPT Image Apr 12, 2025, 02_11_21 AM_

So what’s the cure for Infostealers?
There’s no way to erase stolen data from the dark web.
Mitigation is the only option: continuous monitoring of new leaks and instant password and session resets .
Then, the moment your data is exposed, you’ll hear it from us, not from the media or the headlines.

bottom of page