01Initial access
The victim runs a malicious attachment, installer, cracked application or other payload delivered through social engineering or a compromised channel.
en
Explore documented info-stealer families, variants and observed log or panel formats — and the behaviors defenders can investigate.
How the threat works
An information stealer is malware designed to collect valuable data from an infected device. Depending on the family, that can include browser credentials, session cookies, autofill data, cryptocurrency wallet material, files and device metadata. The collected data is usually packaged and sent to an operator for account takeover, fraud or resale.
01The victim runs a malicious attachment, installer, cracked application or other payload delivered through social engineering or a compromised channel.
02The malware enumerates supported applications, extracts selected data and prepares a structured package for exfiltration.
03Operators receive the stolen records and may use or sell them. A historical observation does not prove that a credential is still valid today.
Curated research snapshot
Select a row to load its curated public profile, including structured target and ATT&CK mappings.
192 entries in this catalog
This catalog covers entries CyStack analysts have tracked or documented while processing leak datasets and conducting threat-intelligence research. Entries may represent a family, variant, bundle, notice, stub or observed log or panel format; this does not imply that CyStack originally discovered every threat represented.
| Entry | Typical targets | ATT&CK | Related labels |
|---|---|---|---|
Typical targets4 | ATT&CK5 | Related labels0 | |
Typical targets3 | ATT&CK5 | Related labels0 | |
Typical targets4 | ATT&CK5 | Related labels0 | |
Typical targets6 | ATT&CK7 | Related labels5 | |
Typical targets3 | ATT&CK5 | Related labels0 | |
Typical targets8 | ATT&CK8 | Related labels2 | |
Typical targets4 | ATT&CK8 | Related labels1 | |
Typical targets7 | ATT&CK9 | Related labels2 | |
Typical targets7 | ATT&CK7 | Related labels1 | |
Typical targets0 | ATT&CK5 | Related labels0 | |
Typical targets0 | ATT&CK3 | Related labels0 | |
Typical targets0 | ATT&CK5 | Related labels0 | |
Typical targets6 | ATT&CK6 | Related labels0 | |
Typical targets4 | ATT&CK5 | Related labels3 | |
Typical targets3 | ATT&CK5 | Related labels1 | |
Typical targets2 | ATT&CK6 | Related labels5 | |
Typical targets1 | ATT&CK4 | Related labels3 | |
Typical targets3 | ATT&CK3 | Related labels2 | |
Typical targets0 | ATT&CK5 | Related labels4 | |
Typical targets1 | ATT&CK2 | Related labels3 | |
Typical targets3 | ATT&CK4 | Related labels0 | |
Typical targets0 | ATT&CK5 | Related labels2 | |
Typical targets3 | ATT&CK3 | Related labels3 | |
Typical targets3 | ATT&CK5 | Related labels1 |
This is a curated, non-exhaustive research snapshot — not a live inventory of every active campaign. A CyStack-coined parser or entry label is not definitive malware-family attribution; entries may cover variants, bundles, notices, stubs or observed log and panel formats. Techniques change over time, and the absence of an entry is not evidence that a threat does not exist. Validate important decisions with current security observations and qualified analysis.
Defender's guide
Info stealers are built to turn data on an infected endpoint into reusable access. The exact collection scope varies by family and version, but defenders commonly investigate browser data, application secrets, financial assets and device context.
Saved usernames, passwords, autofill records, cookies and active session material can expose personal and business accounts. A stolen session may remain useful even after a password-only control is changed.
Depending on its capabilities, a stealer may seek cryptocurrency wallet material, messaging or gaming tokens, VPN and FTP credentials, selected files, screenshots or clipboard data.
An infection on a personal or unmanaged device can still expose corporate email, cloud sessions and remote-access credentials, creating an account-takeover and follow-on intrusion risk.
Treat the exposed endpoint and every associated account as an investigation scope, not just a password-reset task. Isolate and examine the device, revoke active sessions, reset credentials from a known-clean system, rotate exposed tokens or keys, review authentication activity and monitor for follow-on access. Historical leak data is an investigative lead; validate current impact with endpoint and identity telemetry.
Turn intelligence into action
CyStack Intel helps security teams investigate leaked credentials and infostealer observations associated with their organization.