Infostealer
Malware that silently harvests saved passwords, browser cookies and session tokens, autofill data, and crypto-wallet files from an infected device, packaging the loot into 'logs' that are sold on criminal markets and used for account takeovers.
Also known as: stealer malware, stealer log, info-stealing malware, credential stealer
Last reviewed: 1 August 2026
An infostealer is a class of malware built for one job: sweeping a device for everything valuable and sending it to the attacker. A typical stealer grabs the passwords saved in web browsers, the cookies and session tokens that keep users logged in to sites, autofill data such as names, addresses, and payment card details, screenshots, lists of installed software, and files associated with cryptocurrency wallets. It usually runs once, exfiltrates quickly, and may delete itself — many victims never know they were infected.
Infostealers spread through the same channels as other malware: cracked or pirated software, fake installers and 'free' game cheats, malicious ads and search results, phishing attachments, and booby-trapped downloads. The stolen data is bundled into a package criminals call a 'log' — one victim's credentials, cookies, and system fingerprint — and sold cheaply in bulk on underground markets and messaging channels, often through a stealer-as-a-service model where developers rent the malware to affiliates.
Infostealers are the engine behind a large share of account-takeover fraud, and they explain many cases where victims are 'hacked despite 2FA': a stolen session cookie lets an attacker import an already-authenticated login into their own browser, bypassing the password and two-factor prompt entirely, because the site believes it is resuming the victim's existing session. Stolen logs feed follow-on crimes ranging from bank and email takeovers to corporate network intrusions that begin with one employee's infected personal machine.
Defences are unglamorous but effective: never install cracked software or unofficial 'free' versions of paid tools, be wary of downloads promoted through ads and unsolicited links, keep devices and browsers updated with reputable security software, and prefer a dedicated password manager over browser-saved passwords. If you suspect an infection, treat every credential and active session on that device as compromised — change passwords from a clean device and sign out all sessions everywhere, since changing a password alone does not always invalidate stolen session cookies.
Examples
- A user installs a 'cracked' version of a paid design program; within minutes, every password saved in their browser and their active login sessions are exfiltrated and offered for sale as a log.
- A victim's email and crypto-exchange accounts are taken over without any 2FA prompt — the attacker imported session cookies stolen by an infostealer, so the sites treated the attacker as an already-logged-in user.
- A gamer downloads a 'cheat tool' promoted in video comments; the tool is an infostealer that grabs their game, social media, and payment credentials in one pass.