At a glance
Information stealer malware is a type of malware that secretly steals data from your device, such as passwords and banking details. It spreads through fake links, downloads, or email attachments and runs unnoticed in the background. The stolen information can be used for fraud, to take over accounts, or sold online. Keep your device updated, avoid suspicious links, and use strong passwords with multi-factor authentication. Organisations should train staff, limit access, and monitor for unusual activity.
If you think you have any type of malware on your device, find out how to recover.
What is information stealer malware
Information stealer malware (also known as ‘info stealers’) is a type of malware that secretly collects information from your device.
Cybercriminals use different methods to get the malware onto your device:
- Phishing scams: Fake emails or messages with harmful links or attachments.
- Non‑phishing scams: Malicious advertising, risky downloads like cracked or pirated software, and fake search results (search engine poisoning) that trick you into visiting malicious websites.
Once installed, the malware secretly collects your data and personal information for cybercriminals. They may use the information themselves or sell it to others, who can then carry out more attacks or target more victims.
Info stealers can collect different types of data, including:
- user credentials: usernames, passwords, session logins, security keys, backup codes, and access to services like virtual private networks (VPNs) and file transfer protocol (FTP)
- browser data: browsing and search history, cookies, and saved details like passwords and credit or bank card information
- communication data: email and messaging chat logs
- files and documents: financial records, business data, and cryptocurrency wallets or keys
- device information: details about your computer, such as the operating system, internet protocol (IP) address, installed apps, and security software (for example, antivirus)
- images: screenshots taken from your device that may capture private information.
With access to your personal or financial accounts, cybercriminals can commit identity theft, steal money or take control of your accounts. Stolen workplace credentials can lead to larger attacks like ransomware, data breaches or account compromise.
Warning signs of information stealer malware
Info stealers are designed to be undetectable. You may not know your device is infected or that your data is being stolen. Many info stealers can also remove themselves from devices after stealing your data. This is why it is important to protect your devices and accounts early.
Info stealers can be hard to detect. There are some warning signs you can look out for, including:
- unusual account activity, such as configuration changes, unusual or concurrent logins, password changes and blocked access to your accounts
- unexpected, unauthorised transactions on your bank accounts
- more spam calls, emails or messages
- increased communication with companies you haven’t conducted business with before.
Many of the red flags are similar to general malware. You can learn more by checking out the warning signs of malware.
How to prevent information stealer malware
There are some simple steps you can take to reduce the risk of info stealers.
- Secure your main accounts (banking, email, government, and work accounts).
- Use passkeys wherever possible, where this is not possible, use strong, unique passwords.
- Use a trusted password manager.
- Turn on multi‑factor authentication (MFA) wherever possible.
- Keep your devices and software updated.
- Avoid clicking suspicious links or pop‑ups.
- Only download apps and files from trusted sources.
- Make sure your antivirus software is on and up to date.
- Use secure devices for important logins (avoid shared computers).
- Be careful what you store in your web browser’s autofill feature (avoid saving sensitive information like passwords or credit cards details).
- Don’t store your work credentials in a personal password manager unless explicitly approved by your employer.
- Log out of accounts and clear browser data after use.
Learn more about how to protect yourself online through our personal cyber security handbook.
What organisations can do
Organisations may not always be able to control every device connected to their network, especially personal devices used by remote staff. Because of this, they should focus on protecting accounts and preventing stolen login details from being used.
To stay secure, organisations should implement the following controls.
Provide cyber security awareness training for staff
Provide effective training to staff so they can recognise and avoid targeted scams, and harmful file downloads. This training should increase awareness of info stealers, how they spread and the risks to your organisation.
Secure corporate accounts
These actions can help secure your accounts from info stealers:
- Implement MFA on all systems and accounts, including email, VPNs and sensitive data. Use phishing-resistant MFA where possible. Learn more about MFA.
- Disable accounts that are no longer needed to reduce risk.
- Limit administrator access by using secure devices for administration tasks, and separate accounts for everyday use. Learn more about administrator access.
- Apply the principle of least privilege so users only have the access they need, and restrict administrator accounts from accessing the internet, web services or email unless required.
- Regularly manage and review privileged accounts, update passwords (especially for remote access), and monitor for unusual activity.
- Consider implementing just-in-time administration for systems and applications.
- Limit how long sessions stay active by setting timeouts for logins and cookies to reduce the risk of misuse.
Harden enterprise mobility
Strengthen enterprise mobility through these measures:
- Carry out a risk assessment to understand how mobile and personal devices may affect your organisation’s security. Apply steps to strengthen their protection by implementing enterprise mobility hardening.
- If staff use their own devices for work, set clear BYOD (bring your own device) rules, as managed work devices are more secure.
- Review supply chain risks from third-party providers, such as cloud services and managed service providers. Ensure they don’t introduce security weaknesses into your network. Follow our advice on how to manage your security when engaging a managed service provider.
Protect your corporate network
Protect your systems and data by implementing the following measures:
- Keep systems secure by regularly updating applications and operating systems.
- Use strict controls so only approved software can run and separate your network into sections to limit access based on roles.
- Monitor user activity, especially for remote staff, and watch important accounts to detect unusual behaviour or large data transfers.
- Put controls in place to prevent sensitive data from being shared or transferred without approval.
Develop a cyber security incident response plan
Ensure that staff know what policies and procedures to follow and who to contact if they suspect they’ve downloaded a suspicious file and or might have a compromised device.
Your organisation should also be familiar with our Australian Cyber Security Hotline 1300 CYBER1 (1300 292 371). The hotline is available 24 hours a day, 7 days a week.
Implement the Essential Eight maturity model
Protect your networks by implementing any remaining Essential Eight mitigation strategies to strengthen your organisation’s overall cyber security. Learn more about the Essential Eight.
Become a cyber security network partner
Our Cyber Security Network Partners have access to our Cyber Threat Intelligence Sharing (CTIS) service. CTIS is a two-way sharing platform that enables government and industry partners to receive and share information about malicious cyber activity.
We track info stealer activity and share details of active command and control infrastructure through the CTIS platform.
Protect your organisation and customer data from cybercriminal threats by becoming an ASD partner.
Never miss a threat
Sign up to receive the latest cyber security alerts, along with information on emerging threats and how to stay secure online.