All chapters

Chapter 2

How infostealers actually work

Understanding how these tools operate explains why traditional defences so often miss them — they are built to evade detection while maximising stolen value.

Infection

Malicious download, phishing link, or trojanised software — often shockingly mundane: a cracked app on a home machine that also touches corporate VPN.

Harvesting

Stealers comb browser stores (Chrome, Firefox, Edge), autofill, wallets, VPN configs, SSO tokens, and internal app credentials — methodically and quietly.

Exfiltration

Data is compressed, encrypted, and sent to attacker-controlled infrastructure. Operators often appear fileless, signed, or injected into legitimate processes.

Monetisation

Credentials are sold downstream to gangs and brokers — fuelling ransomware, fraud, and espionage at industrial scale.

The most dangerous piece is often the session cookie. Unlike passwords, valid session tokens can be replayed without MFA — pass-the-cookie is now standard in the ransomware playbook.