惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog RSS Feed
量子位
Recent Announcements
Recent Announcements
T
The Blog of Author Tim Ferriss
美团技术团队
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - Franky
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
大猫的无限游戏
大猫的无限游戏
V
Visual Studio Blog
博客园 - 聂微东
aimingoo的专栏
aimingoo的专栏
Microsoft Security Blog
Microsoft Security Blog
U
Unit 42
J
Java Code Geeks
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
L
LangChain Blog

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt
A CISO
Karen Kent · 2026-06-22 · via Search Security Resources and Information from TechTarget

Infostealers aren't new. But what is new is that almost anyone -- regardless of skill -- can now deploy the malware. Update incident response plans to safeguard your operations.

Infostealers do exactly as their name implies: The malware secretly steals sensitive information, such as passwords and financial information, from user endpoints and then transfers that information to a location selected by the attacker.

Infostealers have become far more prevalent in recent years, underpinning dark web markets where attackers actively buy, sell and trade the sensitive data they acquire. Unlike ransomware, where attackers draw attention in hopes of soliciting ransom payments, infostealers do their thievery in silence.

Let's examine how infostealers work to provide CISOs, security leaders and practitioners with infostealer prevention and detection recommendations.

How infostealers work

Infostealers typically employ a botnet architecture. Under a malware-as-a-service model, attackers essentially rent or subscribe to infostealers, configure them as desired and then launch attacks against endpoint targets. Attack methods vary widely, ranging from phishing attacks and malicious links to social engineering and silent drive-by downloads.

Successful attacks infect user endpoints, which then become bots themselves, providing bad actors with command-and-control capabilities. Some infostealers do more than just steal data -- for example, installing additional malware.

Infostealers aren't new. Malware has been stealing data for decades … What is new is how easy it has become for anyone, regardless of skills, to use infostealers at scale.

Attackers primarily seek user credentials, including usernames, passwords and secret cryptographic keys. They might also look for crypto wallets, bank account information and other financial data. Other common targets include:

  • Documents, spreadsheets and other files containing sensitive information.
  • Web browser history, cookies and autofill values, such as saved passwords and credit card numbers.
  • Technical information about the endpoint itself, its OS and its applications that can help attackers to plan future attacks.

How to respond to an attack

Infostealers aren't new. Malware has been stealing data for decades, and the methods infostealers use to infect endpoints, such as phishing and drive-by downloads, aren't new either. What is new is how easy it has become for anyone, regardless of skills, to use infostealers at scale. As a result, organizations are likely to face an increasing number of infostealer attacks.

Enterprise incident response plans and procedures should already address the gamut of infostealer attacks. However, considering their frequency and impact -- such as enabling access to admin accounts and decrypting and stealing sensitive information -- it is worth reviewing incident response programs with infostealers in mind. For example, investigate how the organization would respond to a widespread infostealer attack affecting many endpoints simultaneously. Adjust processes and priorities as needed to reflect the significance of infostealer attacks. And be sure to include infostealer scenarios in incident response tests and exercises.

How to detect and prevent infostealers

Detecting and preventing infostealers requires using all of the tools designed to safeguard your operations, including the following:

  • Train users on cybersecurity basics, especially cyber hygiene and acceptable use.
  • Use antimalware, antiphishing and antispam technologies on endpoints and on network-based devices to prevent infostealers from reaching endpoints and being installed.
  • Keep all endpoints fully patched, properly configured and hardened to minimize their attack surfaces and their exploitable vulnerabilities.
  • Continuously monitor all endpoints, email servers, networks and other associated systems for the presence of infostealers and infostealer command-and-control communications.
  • Enforce the principle of least privilege.
  • Use allowlisting/denylisting technologies on endpoints to restrict which applications can be executed.
  • Constantly monitor endpoint logs and cybersecurity technology logs to identify signs of attempted and successful infostealer installation and use.
  • Avoid using passwords only for credentials; instead, require MFA or other stronger authentication factors.
  • Encrypt sensitive information at rest to make it more difficult for infostealers to access.
  • Consider prohibiting the use of web browser autofill features, which could make it easier for infostealers to access passwords, financial account numbers and other sensitive data.

    Karen Kent is the co-founder of Trusted Cyber Annex. She provides cybersecurity research and publication services to organizations and was formerly a senior computer scientist for NIST.

    Dig Deeper on Threat detection and response