CourionAI
EN
Newsletter
← Glossary Term

infostealer

Cheap, mass-market malware that quietly copies saved passwords, browser cookies and other credentials off a computer and ships them to whoever deployed it.

An infostealer is the plumbing of ordinary cybercrime. It is not designed to lock your files or spy on you for months. It runs once, sweeps up everything useful it can find, saved passwords, browser login cookies, credentials belonging to other apps on the machine, sends it all off, and often removes itself. The harvested data then gets sold in bulk to people who sort through it looking for accounts worth using. Vidar, LummaC2, StealC, RedLine and Acreed are common families on Windows; Atomic Stealer, or AMOS, targets Macs.

Almost all of it arrives the same boring way: pirated software, cracked installers, fake downloads, and apps from somewhere that is not the official source. That makes it unusually preventable. It also makes it dangerous in a way people underestimate, because the stolen cookies let an attacker walk into an account without ever needing your password or your second factor.