Information stealer malware, also known as info stealers, is a type of malware designed to secretly collect information from a victim’s device.
In general, info stealers are capable of stealing:
- user credentials: computer session logins and passwords, browser login links, usernames, passwords, secret keys, Two-Factor Authentication (2FA) backup codes, server passwords, Virtual Private Networks (VPNs) and File Transfer Protocol (FTP) details.
- browser data: browser history, search history, session cookies, and autofill data, such as saved credit/bank card details
- communication data: messaging and email chat logs
- documents and text files: financial information, corporate data, crypto private keys and crypto wallets
- computer information: including operating system details, metadata, Internet Protocol (IP) addresses, applications installed on the computer, anti-virus software used, and end-point detection capabilities
- images: including screenshots of the desktop taken by the malware.
When cybercriminals steal sensitive information, they often use it themselves or sell/trade it to other cybercriminals to target more victims. With access to personal and financial accounts, they can carry out identity theft, financial fraud, and account takeovers.
Theft of your corporate credentials can lead to larger scale incidents, including ransomware, data extortion and more.
Potential warning signs that your information has been stolen
Info stealers are designed to be undetectable, so you may not know your device is infected or that your data is being stolen. Many info stealers can also remove themselves from devices after stealing your data. This highlights the importance of taking steps now to protect your devices and accounts, before you become a victim.
Info stealer malware may be able to avoid your detection, but there are warning signs that your information has been stolen, for example:
- you notice unusual account activity, such as configuration changes, unusual or concurrent logins, password changes and blocked access to your accounts
- you notice unexpected, unauthorised transactions on your bank accounts
- you start to get more spam calls, emails or messages
- you notice increased communication with companies you haven’t done business with before.
For more potential warning signs, read our malware and account compromise threat pages.
You can also find out if your information has been stolen or leaked from:
- the organisation involved in a data breach notifying you
- services that search for your information in data breaches, such as have I been pwned.
If your data has been stolen or leaked, learn more on how to report and recover from a data breach and how to report and recover from account compromise.
How you may fall victim to info stealers
Cybercriminals use many techniques to infect victim devices with info stealer malware. These include:
- Phishing campaigns – such as adding malicious attachments or links to emails or spreading the malware via fake messages.
- Non-phishing methods – such as malicious advertising and websites laced with malicious software, including cracked and pirated software, as well as search engine poisoning.
Once your device is infected, the malware silently collects your information and sends it back to a remote server controlled by cybercriminals. These cybercriminals may then target you directly, or more likely, will sell the data. The data is generally sold in centralised ad-hoc marketplaces or platforms, such as Telegram or dark web hacking forums. Cybercriminals that buy the data can then launch further attacks or target more victims.
The threat of information stealers to your personal information
Below are examples of how cybercriminals monetise the different types of data stolen.
Data may be used to gain access to a victim’s social media and other accounts, leading, but not limited, to:
- unauthorised access to personal email or social media accounts
- risk of identity theft
- loss of privacy
- increased risk of social engineering and phishing attacks.
Data may be used to gain access to a victim’s finances, potentially leading to:
- accessing funds
- unauthorised purchases
- fraudulent charges
- identify theft
- unauthorised loan applications.
Data may be used to gain access to a victim’s employer, their clients and their enterprise systems. This could lead to:
- extortion
- ransomware
- data breach
- business email compromise
- theft of intellectual property
- theft of sensitive information.
Security tips for protecting your information from info stealers
While we work closely with law enforcement and industry to help protect individuals from cybercriminals, there are some simple actions you can do to reduce the risk of info stealers. As a start, we suggest you focus on strengthening the security of your most important online accounts. This includes your:
- internet banking account
- email accounts
- accounts for government services and websites
- remote working accounts.
Don’t stop there, learn more about how to secure your devices.
Key actions include:
- setting up multi-factor authentication (MFA), such as a passkey where available
- using a reputable password manager
- using unique, complex and long passphrases or passwords
- install software updates as soon as they are available.
Key security tips to avoid info stealers:
- Be wary of clicking on links in emails, messages, pop-ups, and advertisements.
- Only download software from trusted sources – avoid pirated software and downloading files or software from unknown or untrusted sources.
- Ensure that your operating system's built in antivirus solution is enabled. If you use a third-party antivirus solution, ensure that it is kept up to date and is from a reputable vendor.
Key security tips to protect your information:
- Use a trustworthy computing device when logging into important online accounts. For example, don’t log in to your work accounts or use sensitive services like internet banking on shared computers or communal workstations.
- Be careful with what you store in your web browser’s autofill feature. When filling in web forms, consider manually entering sensitive data, such as credit card numbers, rather than saving it to your web browser's autofill feature.
- Do not store your work credentials in a personal password manager unless explicitly approved by your employer. This includes your web browser’s password manager. If in doubt, request that your employer provide a corporately supported password manager.
- When logging into online accounts, avoid using any ‘remember me’ options.
- Log out from all online services and clear web browser cookies after finishing a browsing session in order to reduce the information available to info stealers.
Security tips for protecting your organisation from info stealers
Organisations may not be able to enforce controls on devices that connect to their corporate network, particularly on personal devices used by employees working remotely. ASD’s ACSC recommends organisations focus on implementing controls to protect themselves from the exploitation of valid credentials. ASD’s ACSC recommends:
Provide cyber security awareness training for staff
- Prevent successful targeted social engineering and malicious file downloads by providing effective training to staff.
- Raise awareness of info stealers, their delivery methods and the phishing threats to your organisation.
Secure corporate accounts
- Implement MFA:
- Implement MFA across external and internal services, systems and sensitive data repositories, particularly for webmail, VPNs, and privileged user accounts that access critical systems. Best practice is to implement phishing-resistant MFA on all accounts.
- Disable user accounts when they are no longer required.
- Restrict administrator privileges:
- Perform network administration and other privileged tasks using a dedicated locked-down workstation only (i.e. a secure admin workstation).
- Follow least-privilege best practice by requiring administrators to use privileged user accounts for managing systems and standard user accounts for non-administrative tasks.
- Prevent privileged user accounts (excluding those explicitly authorised to access online services) from accessing the internet, email and web services.
- Consider implementing just-in-time administration for systems and applications.
- Enforce the management and auditing of privileged user accounts.
- Update passwords periodically, particularly external-facing remote-access accounts.
- Enforce lifespan time outs and sunset policies on session tokens and cookies.
Harden enterprise mobility
- Perform an enterprise mobility risk assessment and implement enterprise mobility hardening guidelines.
- Implement a Bring Your Own Device (BYOD) policy if you allow employees to use personal devices for work, as corporately managed devices are more secure than unmanaged personal devices.
Review and assess supply chain risks from vendors accessing your networks, including Software-as-a-Service (Saas) vendors and Managed Service Providers. How to Manage Your Security When Engaging a Managed Service Provider.
Protect your corporate network
- Keep applications and operating systems up to date.
- Apply local security policies to enforce application control with a strict allow list.
- Implement network segmentation to separate network segments based on role and functionality.
- Audit and monitor user activities, especially for remote employees.
- Monitoring privileged accounts can reveal unauthorised access to sensitive data or unusual data transfer activities, such as large volumes of data uploaded to an external network.
- Implement data-loss prevention policies and tools to prevent unauthorised data transfers.
Become an ASD Cyber Security Network Partner and join ASD’s Cyber Threat Intelligence Sharing (CTIS) service
- CTIS is a two-way sharing platform that enables government and industry partners to receive and share information about malicious cyber activity.
- ASD’s ACSC is tracking info stealer activity and shares details of active command and control infrastructure through the CTIS platform.
- Sign up to become a partner and protect your organisation and customer data from cybercriminal threats.
Be prepared for a compromise
- Develop a cyber security incident response plan to use in the event of an info stealer compromise.
- Ensure that employees are aware of what to do and who to contact if they suspect they have downloaded a suspicious file.
- Ensure that your organisation is familiar with ASD’s Australian Cyber Security Hotline 1300 CYBER1 (1300 292 371).
Implement ASD’s ACSC’s Essential Eight
- In addition to the mitigations mentioned above, ASD’s ACSC strongly recommends implementing the remainder of ASD’s ACSC’s Essential Eight.
More information
Report and recover from malware
If you’ve fallen victim to a malware attack, find out what to do and who to contact.
Report and recover from account compromise
A guide to recovering your account and protecting you against future attacks.
The silent heist: cybercriminals use information stealer malware to compromise corporate networks
Information stealer malware steals user login credentials and system information that cyber threat actors exploit, predominantly for monetary gain.