Infostealer malware is a class of credential-theft malware referenced here as compromising devices and harvesting credentials and other sensitive data from infected systems. The content states that recent infostealer strains have been observed bypassing recent Google Chrome security patches, enabling theft of credentials and sensitive data despite browser security updates. It is also described as being installed on victims’ devices through social-engineering scenarios in which a fake support representative convinces a user to grant remote access, after which banking credentials are stolen or infostealer malware is deployed. The malware’s output is reflected in large-scale credential ecosystems: stolen credentials captured from infected devices are collected from infostealer logs and then shared, merged, and resold via Telegram channels, Tor sites, and underground forums. One cited dataset aggregated real credentials from infostealer malware logs at very large scale. The content also links infostealer-derived credential theft to a real-world intrusion in the automotive sector: Scania’s external IT partner was reportedly compromised by infostealer malware, and the stolen partner credentials were then used in the May 28–29, 2025 breach of Scania, resulting in theft and extortion involving insurance claim documents. High-confidence impacts mentioned include theft of banking credentials, account credentials, and sensitive data from infected devices; use of stolen credentials for follow-on intrusions; and contribution to underground credential markets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The post further revealed that a government employee accidentally infected their computer with infostealer malware back in 2016. The malicious software exposed the employee’s username and password. It is shocking that this password was never changed over the last ten years, and was the same as the username.
The post further revealed that a government employee accidentally infected their computer with infostealer malware back in 2016. The malicious software exposed the employee’s username and password. It is shocking that this password was never changed over the last ten years, and was the same as the username.
The post further revealed that a government employee accidentally infected their computer with infostealer malware back in 2016. The malicious software exposed the employee’s username and password. It is shocking that this password was never changed over the last ten years, and was the same as the username.
The group distributed infostealer malware disguised as a game-enhancement tool.
The post further revealed that a government employee accidentally infected their computer with infostealer malware back in 2016. The malicious software exposed the employee’s username and password. It is shocking that this password was never changed over the last ten years, and was the same as the username.
Naz.API is different. It’s a 71-million-credential stealer log, credentials captured directly from infected machines by infostealer malware, in cleartext, at the moment of theft. No hashing. No cracking required. Username, password, and the URL it was entered on, all captured live.
Infostealer Malware: Harvesting session tokens and login credentials from employees or affiliated hosts to quietly bypass multi-factor authentication.
And once you have that, you don’t need passwords anymore. You’ve got sessions, tokens and access.
Attackers can reuse valid session cookies to access accounts without triggering a password prompt or multi-factor authentication (MFA)
Attackers obtained valid login credentials using infostealer malware, software that silently captures usernames and passwords from infected devices.
Naz.API is different. It’s a 71-million-credential stealer log, credentials captured directly from infected machines by infostealer malware, in cleartext, at the moment of theft. No hashing. No cracking required. Username, password, and the URL it was entered on, all captured live.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware designed to steal credentials and sensitive information from infected systems, enabling further attacks such as unauthorized access and data theft.
Infostealer malware is designed to steal sensitive information such as banking credentials from infected devices, often delivered through tech support scams targeting the elderly.
Infostealer malware is designed to steal credentials and other sensitive information from infected devices. The stolen data is then aggregated and sold or shared on underground forums, Telegram channels, and other dark web marketplaces. This type of malware is a primary source for large-scale credential dumps and fuels the digital supply chain of credential theft.
Malware designed to steal sensitive information from victims, noted for its ability to bypass recent Chrome security patches.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.