Infostealer
An infostealer is malware designed to exfiltrate credentials, cookies, browser sessions, and cryptocurrency wallets from infected endpoints. Infostealer logs are a major source of initial-access credentials sold on criminal markets and linked to follow-on ransomware.
Frequently Asked Questions
What is Infostealer?
An infostealer is malware designed to exfiltrate credentials, cookies, browser sessions, and cryptocurrency wallets from infected endpoints. Infostealer logs are a major source of initial-access credentials sold on criminal markets and linked to follow-on ransomware.
How is Infostealer related to Malware?
Infostealer and Malware are both key concepts in threat intelligence. Malware is any software designed to harm, exploit, or gain unauthorized access to a system. It includes viruses, worms, trojans, ransomware, spyware, adware, rootkits, and more. Detection relies on file hashes, behavioral signatures, and threat intelligence feeds.
Related Terms
Malware
Malware is any software designed to harm, exploit, or gain unauthorized access to a system. It includes viruses, worms, trojans, ransomware, spyware, adware, rootkits, and more. Detection relies on file hashes, behavioral signatures, and threat intelligence feeds.
C2 Infrastructure
Command-and-control (C2) infrastructure is the server, domain, or cloud resource malware uses to receive instructions and exfiltrate data. Blocking C2 IPs and domains at the firewall and DNS layer disrupts active infections before lateral movement.
Initial Access Broker (IAB)
An initial access broker is a threat actor or service that sells footholds — compromised VPN credentials, RDP access, or web shells — to other criminals who deploy ransomware or data theft. Tracking IAB infrastructure helps prioritize blocking and hunting before payloads land.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.