Back to glossary

Infostealer

2 min read

In criminal operations, an infostealer is malware built for one job: harvest credentials, session cookies, browser data and files from a machine, send them to the operator and leave. It is the origin of a large share of the corporate access sold today, and the reason a stolen session matters more than a stolen password.

July 29, 2026
Compartir:

How it works

Execution is short, often seconds. The payload reads browser credential stores and cookie databases, application configuration holding tokens, messaging and cryptocurrency wallet data, and files matching patterns of interest, then packages the result and exits without installing anything. The absence of persistence is deliberate: there is nothing to find afterwards.

The output is a log, sold in bulk on criminal marketplaces or distributed through channels, containing the credentials, the cookies, the machine name and often a list of the software installed. Buyers search those logs for a corporate domain, which is how one employee’s personal device becomes an entry point into a company that never had a security event of its own.

What goes wrong

The session cookie is the part that defeats the control everyone deployed. A valid session token is a credential that has already passed authentication, so replaying it in the attacker’s browser bypasses multi-factor authentication entirely: there is no login to challenge. This is the same outcome as session hijacking, arriving through malware instead of through a proxy.

The second issue is where the infection lives. The infected machine is frequently unmanaged: a personal laptop used for a work account, a contractor’s device, a family computer where someone signed into a corporate service once. There is no endpoint agent, no telemetry and nothing to alert, and the first evidence the company will ever have is the log appearing for sale.

Third, the response is usually incomplete. Resetting the password does nothing to a stolen session. Eradication means revoking sessions and tokens, not just credentials, and that is a step most password reset procedures still omit.

Where this shows up in an audit

This is intelligence work rather than testing. Logs are monitored for the client’s domains, and what comes back is specific: the accounts, the applications, whether the token is still valid and how old the exposure is. It is one of the few findings a client can act on the same day, and it is the raw material an access broker works from. The recommendation is always the same pair: revoke sessions as well as passwords, and treat unmanaged devices holding corporate sessions as in scope. This is part of how we monitor for your credentials in criminal marketplaces.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.