What it is
An infostealer is malware designed to steal saved credentials, session cookies, card data and cryptocurrency wallets from the infected device. The data ends up in collections sold online to other criminals.
How it works
- 1It spreads through pirated software, fake updates or installers, malicious ads and attachments.
- 2Once running, it reads passwords saved in the browser, cookies and device files.
- 3The data is sent to the attacker, who uses or sells it.
- 4With a stolen session cookie they can get into an account even without knowing the password.
How to spot it
- Sign-ins to your accounts from places or devices you do not recognise, with no password prompt
- Slower computer or browser, unknown extensions
- Antivirus turned off or programs you do not remember installing
- “New device” alerts after installing a program
How to defend
- Download software only from official sources and avoid cracked programs
- Do not save passwords in the browser: use a dedicated manager with strong authentication
- Keep system, browser and antivirus updated
- Use passkeys: they cannot be stolen and reused like a password
- In companies: separate work computers from personal ones and monitor leaked credentials
If you think you have been hit
- Isolate the device and clean it, ideally by reinstalling, before changing passwords
- From a clean device change all passwords and sign out of all sessions
- Tell your bank and check recent access to your main accounts
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026