top of page
The Growing Threat from Infostealers
Infostealers are a relatively new type of malware designed to steal confidential information from infected devices. Their rise began in 2018 and has accelerated every year, reaching a staggering 100 million infected PCs globally by 2024.
This is due to their strong commercial focus, they are key components of a sophisticated and widespread cybercrime industry.
The main goal of infostealers is to locate and exfiltrate sensitive information and sell it to other cybercriminals on dark web markets.
So, how do you get infected?!
- Pirated software such as free licenses for photoshop, video game cheats, mods for video games, etc
- Supply chain attacks from hijacked NPM packages, malicious Visual Studio extensions, open-source software, or even infected commercial software
- From Google Ads when you search for software and install from a malicious ad appearing at the top of search results
- Fake Captcha/System update (ClickFix) that takes advantage of social engineering and human trust
- Someone shared a link
in a game chat, Discord,
Whatapp, Facebook, or X






What information do infostealers steal?
Each infected device's data stored with such folder tree structure

Infostealers steal data from across the victim's system, including browser autofill data, passwords, session tokens, credit cards, and more.


Does 2FA Prevent Account Exposure? (No)
Browser cookies are used to represent an already authenticated web session, the method of original authentication does not matter, whether it was a passkey, MFA-validated, or logged-in using Single Sign-On (SSO). One stolen cookie is all it takes to bypass the entire authentication and login process. Users “fingerprints” are included with the credentials too so criminals can easily bypass attempts to detect fingerprint mismatches too.




The Personal and Business Damage of an Infostealer Leak
Personal Damage:
Unauthorized access to documents: Gmail, Outlook, Dropbox, iCloud
(mostly used to get access to other services, sell account or send spam)
Steel money from: Crypto wallets, Paypal, Casinos, Wise, Revolut, Banks
Documents from desktop used for brute-force attacks on crypto wallets
Steal digital assets from Games: Steam, Riot Games, Epic Games, Minecraft, etc
Social media: Facebook, Instagram, X, Netflix
Messengers: Telegram, Whats'up, Discord
used for reselling accounts or for malware spreading
Services: Uber, Axis, Ring, VPN, Vodafone, O2, ChatGPT, Amazon
Used to collect private data and to make fraudulent purchases using your account.
Sensitive data: Tinder, Pornhub, Adultfriendfinder, Baidu, Onlyfans, DNA collections, other medical services or Government sites for tax reports etc
Used for blackmail and fraud
Business Damage:
Unauthorized access to documents: Webmail, Jira, Zendesk, DropBox
Corporate access: SSO(okta, microsoft), VPN, SSH keys/certs
Corporate Messengers: Slack, Teams, Discord, Zoho, CRM/ERP systems
Other services: Github, AWS, SnowFlake, ChatGPT, Godaddy, Linkedin
Historical Infostealer Leaks:
Only in 2024 these
companies were hacked
by account takeover attacks
gained access to
SnowFlake cloud DB
using stolen credentials
harvested from
infostealer infection
For instance, a Slack account cookie bought on the dark web for $10 led to the compromise of Electronic Arts 780GB game source codes.

So what’s the cure for Infostealers?
There’s no way to erase stolen data from the dark web.
Mitigation is the only option: continuous monitoring of new leaks and instant password and session resets .
Then, the moment your data is exposed, you’ll hear it from us, not from the media or the headlines.
bottom of page