Most password attacks are guessing games - Brute force, spraying, dictionary runs. Infostealers skip the game entirely. This class of malware runs on your machine for a few seconds, harvests every password your browser has ever saved, every cookie keeping you logged in, your autofill data and your crypto wallet files, ships the bundle to the attacker, and frequently deletes itself. No guessing. No cracking. Total collection.

Security teams now rank infostealers among the top drivers of account takeover, and the numbers back the ranking: IBM's X-Force threat report measured a 266% year-over-year surge in infostealer activity in its 2024 edition, and the Verizon Data Breach Investigations Report has for years put stolen credentials at the top of the list of ways attackers get in. If credential theft were a market - And it is - Infostealers would be its biggest supplier.

Sixty seconds on an infected machine

A modern stealer - Families like Lumma, RedLine, Vidar and Raccoon have dominated recent years - Is a smash-and-grab tool, not a lurker. On execution, it typically collects:

  • Saved browser passwords. Chrome, Edge, Firefox and friends encrypt saved logins, but they must be able to decrypt them for autofill - And malware running as you, inside your session, can generally invoke the same decryption path. Every saved login exits in plaintext.
  • Session cookies. The tokens that keep you signed in to Gmail, your bank and your work SSO. More on why these are the crown jewels below.
  • Autofill data. Names, addresses, phone numbers and, where saved, payment cards.
  • Crypto wallet files and browser extensions. Seed vaults from MetaMask-style extensions and desktop wallets.
  • Files matching keywords. Many stealers grab documents whose names contain strings like password, seed or wallet - That passwords.xlsx on your desktop is explicitly on the shopping list.
  • A machine fingerprint. OS, hardware, IP, installed software - Packaging the loot for resale.

The whole package is called a log, and it uploads in seconds. Antivirus that detects the stealer an hour later has detected a burglar who already left.

The log economy

Infostealers are malware-as-a-service. Operators rent the kit to affiliates for a monthly fee; affiliates handle distribution; the logs flow into Telegram channels and dark-web markets where they sell for a few dollars each - Or get given away in bulk to build a channel's reputation. Specialized buyers then mine the logs: one crew extracts banking sessions, another hunts corporate SSO credentials to resell to ransomware groups, another drains crypto wallets.

Law enforcement takedowns - Like 2023's "Operation Cookie Monster" against Genesis Market, which sold victim identities complete with cookies and browser fingerprints - Remove marketplaces, but the supply chain reroutes quickly.

The most instructive recent case is the 2024 wave of attacks on Snowflake customer accounts, which hit major companies including Ticketmaster and AT&T. Investigators (Mandiant among them) traced the access to credentials harvested by infostealers - Some stolen years earlier - Used against accounts that had no multi-factor authentication. Nothing was "hacked" in the Hollywood sense. Old stealer logs plus missing MFA equaled one of the largest data-theft campaigns of the decade.

What's in a stealer log What attackers do with it
Saved browser passwords Account takeover, resale, credential-stuffing feedstock
Session cookies Log in with no password and no 2FA prompt
Autofill identity + cards Fraud, phishing personalization, identity theft
Crypto wallet data Immediate, irreversible theft of funds
Corporate SSO/VPN logins Sold to ransomware and intrusion crews
Machine fingerprint Impersonating your exact browser to dodge fraud checks

Cookies: the part that bypasses your 2FA

Passwords get the headlines, but session cookies are why defenders fear stealer logs. After you log in - Password, 2FA code, the works - The site hands your browser a session token so you aren't re-challenged on every click. Steal that token and you are that session. An attacker importing your cookies, often paired with your machine fingerprint, walks into the account with no password prompt and no 2FA challenge, because the site believes the login already happened.

This is why "I have 2FA, so a malware infection isn't a crisis" is dangerously wrong. Two-factor authentication protects the login ceremony; a stealer skips the ceremony. (Keep using 2FA - It still shuts down every attack that does have to log in fresh. It just doesn't make an infected machine safe.)

Rule of thumb: after malware runs on a device, nothing typed, saved or logged-in on that device is secret anymore. Recovery starts with the machine, not the passwords.

How machines get infected

Infostealer distribution targets ordinary people doing ordinary things:

  • Cracked software and game cheats - The single most reliable channel. The "free" Photoshop keygen has been a stealer wrapper for years.
  • Malvertising - Poisoned search ads that put a fake download page for popular free tools above the real result.
  • Fake updates - "your browser is out of date" overlays on compromised sites.
  • YouTube and Discord lures - Tutorial videos and pinned links promising mod menus, free software or crypto tools.
  • Phishing attachments - The classic route, covered in depth in our phishing protection guide.

Unlike a keylogger, which records what you type going forward, a stealer monetizes what your machine has already accumulated - Which is why a five-second infection can cost you fifty accounts.

Staying out of the logs

Don't run untrusted executables. No cracked software, no cheat clients, no "codec packs." Download tools only from the developer's real site - Typed, not clicked from an ad. This single habit removes most of the risk.

Rethink where credentials live. Everything your browser can silently decrypt, malware running as you can too - Our breakdown of saving passwords in your browser walks through the nuances. A dedicated vault like our Password Wallet that locks behind a master password you type per session shrinks the always-decryptable surface; pick a master credential you can actually remember with a passphrase generator.

Prefer phishing-resistant, device-bound factors. Passkeys and hardware security keys bind authentication to hardware, so there's no reusable secret in a log.

Keep defenses current. OS and browser updates plus reputable endpoint protection won't catch everything, but they raise the cost meaningfully.

If you suspect an infection: disconnect, then from a KNOWN-CLEAN device change your email password first, revoke all active sessions everywhere ("sign out of all devices"), then rotate remaining passwords in priority order. Reformat the infected machine - Don't trust a scan that says it's clean. Full triage order lives in our guide on what to do after a data breach.

FAQ

How do I know if my credentials are in a stealer log?

Breach-notification services help: haveibeenpwned.com now flags accounts found in stealer logs, and some password managers surface similar alerts. Treat unexpected "new login" emails, sessions you don't recognize, or password-reset notices you didn't request as strong signals. Absence of an alert proves nothing - Most logs are traded privately.

Does antivirus stop infostealers?

Sometimes. Major engines detect known stealer builds, but operators repack their malware constantly to slip signatures, and a stealer needs only seconds of execution to win. Antivirus is worth running as one layer - It is not a substitute for refusing to execute untrusted downloads.

Will changing my passwords fix an infection?

Not by itself, and order matters. If you change passwords from the infected machine, the stealer's operator may capture the new ones too. Clean or reformat the device (or use a different one), then rotate credentials and revoke active sessions so stolen cookies die.

Are phones affected too?

Far less. iOS and Android sandboxing prevents one app from raiding another app's stored credentials, so the classic desktop smash-and-grab doesn't translate. Mobile threats exist - Malicious apps, overlay attacks on Android - But the industrial stealer-log economy overwhelmingly runs on Windows desktops.

Why are years-old stolen passwords still dangerous?

Because passwords outlive the theft. The Snowflake-related intrusions of 2024 used credentials stolen as far back as 2020 that had never been rotated and weren't backed by MFA. A leaked password stays live until you change it - Logs are archives, and attackers mine old ones profitably.