Infostealer
Also called: stealer logs
An infostealer is malware that collects saved passwords, browser cookies, session tokens, autofill data and crypto wallets from an infected computer and sends them to the attacker. The stolen records, called stealer logs, are sold or shared online. Because they can include live sessions, stealer logs can let attackers sign in without a password.
How it works
Infostealers spread through fake software downloads, cracked programs, malicious ads and lures such as fake CAPTCHAs. Once running, the malware copies credentials from browsers and apps within minutes, often on personal devices that also hold work logins, and the attacker or a buyer later uses those credentials against corporate services.
A real example
In June 2024 Mandiant reported that attackers accessed multiple organizations' Snowflake customer instances with stolen credentials obtained primarily from infostealer malware campaigns on systems not owned by Snowflake.
Source: UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion — Mandiant (Google Cloud), 2024-06-10
The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Require MFA on every account, including service and contractor accounts, and bind sessions to the device so stolen cookies cannot be replayed elsewhere. Rotate credentials found in stealer logs.
Related terms
Sources
- UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion — Mandiant (Google Cloud), 2024-06-10
Last reviewed Oct 2, 2026